Vulnerability index

Browse CVEs

33 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2025-48709 BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could … Control M\/server Mitigation only Fix from $1,9502025-08-07 CRITICAL 9.8 CVE-2024-34399 **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac… Remedy Mid Tier Mitigation only Fix from $2,3002024-09-18 HIGH 8.8 CVE-2021-35002 BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… Track It\! Mitigation only Fix from $1,9502024-05-07 MEDIUM 6.5 CVE-2021-35001 BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in… Track It\! Mitigation only Fix from $1,6002024-05-07 MEDIUM 5.4 CVE-2022-26088 An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF … Remedy It Service Management Suite No fix yet Fix from $1,6002022-11-10 CRITICAL 9.8 CVE-2022-24047 This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re… Track It\! Mitigation only Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2017-17674 BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be… Remedy Mid Tier Mitigation only Fix from $2,3002021-05-19 HIGH 8.8 CVE-2017-17677 BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru… Remedy Mid Tier Mitigation only Fix from $1,9502021-05-19 MEDIUM 6.1 CVE-2017-17678 BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utili… Remedy Mid Tier No fix yet Fix from $1,6002021-05-19 MEDIUM 5.3 CVE-2017-17675 BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack … Remedy Mid Tier Mitigation only Fix from $1,6002021-05-19 MEDIUM 6.5 CVE-2015-5071 AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 MEDIUM 6.5 CVE-2015-5072 The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 HIGH 7.8 CVE-2019-17043 An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat… Patrol Agent Mitigation only Fix from $1,9502019-10-14 HIGH 8.8 CVE-2018-18862 BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configura… Remedy Action Request System No fix yet Fix from $1,9502019-03-21 MEDIUM 6.5 CVE-2018-19505 Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act … Remedy Action Request System Server No fix yet Fix from $1,6002019-01-03 MEDIUM 6.1 CVE-2015-9257 BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS. Remedy Action Request System Mitigation only Fix from $1,6002018-03-24 MEDIUM 6.1 CVE-2014-9514 Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5. Footprints Service Core No fix yet Fix from $1,6002017-08-28 HIGH 7.8 CVE-2017-13130 mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid roo… Patrol No fix yet Fix from $1,9502017-08-23 HIGH 7.5 CVE-2016-2349 Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password. Remedy Action Request System Mitigation only Fix from $1,9502016-12-21 CRITICAL 9.8 CVE-2016-4322EPSS 5% BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p… Bladelogic Server Automation Console No fix yet Fix from $2,3002016-12-13 MEDIUM 5.0 CVE-2014-8270EPSS 20% BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy… Track It\! Mitigation only Fix from $1,6002014-12-12 HIGH 7.5 CVE-2014-4872EPSS 80% BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary… Track It\! No fix yet Fix from $1,9502014-10-10 MEDIUM 6.5 CVE-2014-4873 SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL command… Track It\! No fix yet Fix from $1,6002014-10-10 MEDIUM 6.9 CVE-2014-2591 Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect… Patrol Agent No fix yet Fix from $1,6002014-05-14 HIGH 7.5 CVE-2013-4945 Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (… Service Desk Express No fix yet Fix from $1,9502013-07-29 MEDIUM 5.1 CVE-2012-2959 Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote atta… Identity Management Suite No fix yet Fix from $1,6002012-06-11 HIGH 10.0 CVE-2011-0975EPSS 7% Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Perfor… Performance Analysis For Servers Mitigation only Fix from $1,9502011-02-10 HIGH 7.5 CVE-2007-1972 PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers … Performance Manager Mitigation only Fix from $1,9502007-04-22 HIGH 7.5 CVE-2007-2136 Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP po… Patrol Perform Agent Mitigation only Fix from $1,9502007-04-22 MEDIUM 5.0 CVE-2007-0310 BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those… Remedy Action Request System Mitigation only Fix from $1,6002007-01-18