CVE-2017-17674
Critical · CVSS 9.8BMC Remedy Mid Tier — Server Side Request Forgery (SSRF) / Remote File Inclusion (RFI) / Local File Inclusion (LFI)
- CVSS
- 9.8
- nvd
- EPSS
- 2.57%
- 83th pct
- KEV
- No
- Class
- other
- CWE-918
Description
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinting, internal port scanning, Server Side Request Forgery (SSRF), or remote code execution (RCE).
Search profile — drives PoC discovery
Symbols Mid TierRFILFISSRFAR Systemarsysmidtiercacheidformserver
Keywords CVE-2017-17674BMC Remedy Mid TierSSRFremote file inclusionlocal file inclusionRFI LFIBMC AR System9.1SP3Remedy SSRFBMC Remedy RCEfulldisclosure 2017
Versions: 9.1SP3
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://docs.bmc.com/docs/ars91/en/9-1-00-fixes-available-for-remedy-ar-system-security-vulnerabilities-800555806.html
- https://seclists.org/fulldisclosure/2017/Oct/52
- http://bmc.com
- http://remedy.com
- https://docs.bmc.com/docs/ars91/en/9-1-00-fixes-available-for-remedy-ar-system-security-vulnerabilities-800555806.html
- https://seclists.org/fulldisclosure/2017/Oct/52
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z