Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Control M\/server HIGH 7.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …

Mitigation only
Fix from $1,950 2025-08-07
Remedy Mid Tier CRITICAL 9.8
CVE-2024-34399

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac…

Mitigation only
Fix from $2,300 2024-09-18
Track It\! HIGH 8.8
CVE-2021-35002

BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

Mitigation only
Fix from $1,950 2024-05-07
Track It\! MEDIUM 6.5
CVE-2021-35001

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

Mitigation only
Fix from $1,600 2024-05-07
Remedy It Service Management Suite MEDIUM 5.4
CVE-2022-26088

An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF …

No fix yet
Fix from $1,600 2022-11-10
Track It\! CRITICAL 9.8
CVE-2022-24047

This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…

Mitigation only
Fix from $2,300 2022-02-18
Remedy Mid Tier CRITICAL 9.8
CVE-2017-17674

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be…

Mitigation only
Fix from $2,300 2021-05-19
Remedy Mid Tier HIGH 8.8
CVE-2017-17677

BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru…

Mitigation only
Fix from $1,950 2021-05-19
Remedy Mid Tier MEDIUM 6.1
CVE-2017-17678

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utili…

No fix yet
Fix from $1,600 2021-05-19
Remedy Mid Tier MEDIUM 5.3
CVE-2017-17675

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack …

Mitigation only
Fix from $1,600 2021-05-19
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5071

AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"…

No fix yet
Fix from $1,600 2020-01-15
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5072

The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi…

No fix yet
Fix from $1,600 2020-01-15
Patrol Agent HIGH 7.8
CVE-2019-17043

An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat…

Mitigation only
Fix from $1,950 2019-10-14
Remedy Action Request System HIGH 8.8
CVE-2018-18862

BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configura…

No fix yet
Fix from $1,950 2019-03-21
Remedy Action Request System Server MEDIUM 6.5
CVE-2018-19505

Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act …

No fix yet
Fix from $1,600 2019-01-03
Remedy Action Request System MEDIUM 6.1
CVE-2015-9257

BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.

Mitigation only
Fix from $1,600 2018-03-24
Footprints Service Core MEDIUM 6.1
CVE-2014-9514

Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.

No fix yet
Fix from $1,600 2017-08-28
Patrol HIGH 7.8
CVE-2017-13130

mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid roo…

No fix yet
Fix from $1,950 2017-08-23
Remedy Action Request System HIGH 7.5
CVE-2016-2349

Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.

Mitigation only
Fix from $1,950 2016-12-21
Bladelogic Server Automation Console CRITICAL 9.8
CVE-2016-4322EPSS 5%

BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p…

No fix yet
Fix from $2,300 2016-12-13
Track It\! MEDIUM 5.0
CVE-2014-8270EPSS 20%

BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy…

Mitigation only
Fix from $1,600 2014-12-12
Track It\! HIGH 7.5
CVE-2014-4872EPSS 80%

BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary…

No fix yet
Fix from $1,950 2014-10-10
Track It\! MEDIUM 6.5
CVE-2014-4873

SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL command…

No fix yet
Fix from $1,600 2014-10-10
Patrol Agent MEDIUM 6.9
CVE-2014-2591

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect…

No fix yet
Fix from $1,600 2014-05-14
Service Desk Express HIGH 7.5
CVE-2013-4945

Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (…

No fix yet
Fix from $1,950 2013-07-29
Identity Management Suite MEDIUM 5.1
CVE-2012-2959

Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote atta…

No fix yet
Fix from $1,600 2012-06-11
Performance Analysis For Servers HIGH 10.0
CVE-2011-0975EPSS 7%

Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Perfor…

Mitigation only
Fix from $1,950 2011-02-10
Performance Manager HIGH 7.5
CVE-2007-1972

PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers …

Mitigation only
Fix from $1,950 2007-04-22
Patrol Perform Agent HIGH 7.5
CVE-2007-2136

Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP po…

Mitigation only
Fix from $1,950 2007-04-22
Remedy Action Request System MEDIUM 5.0
CVE-2007-0310

BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those…

Mitigation only
Fix from $1,600 2007-01-18