File Inclusion Vulnerability in BMC Remedy AR System Mid Tier
CVE-2015-5072
6.5MEDIUM
What is CVE-2015-5072?
The BIRT Engine servlet in the AR System Mid Tier component of BMC Remedy AR System Server prior to version 9.0 SP1 contains a file inclusion vulnerability. This flaw allows remote authenticated users to access arbitrary files on the server by exploiting the __imageid parameter, potentially exposing sensitive information and compromising the system's integrity.
