BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-8111