Back

CVE-2019-16755

CRITICAL

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.

Published: Sep 26, 2019 Modified: Jun 17, 2026
CWE-502

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
bmc myit_digital_workplace * < 18.08.00

GitHub Security Advisory GHSA-cq5h-qx7v-mjg5

A vulnerability was discovered in BMC MyIT Digital Workplace DWP before 18.11. The DWP component...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.51%

Top 17% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub