AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to navigate to arbitrary files via the __report parameter of the BIRT viewer servlet.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Remedy_ar_system_server | Bmc | 8.0 (including) | 8.0 (including) |
| Remedy_ar_system_server | Bmc | 9.0 (including) | 9.0 (including) |