Vulnerability index

Browse CVEs

75 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Track It\! CRITICAL 9.8
CVE-2022-24047

This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…

Mitigation only
Fix from $2,300 2022-02-18
Remedy Mid Tier CRITICAL 9.8
CVE-2017-17674

BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be…

Mitigation only
Fix from $2,300 2021-05-19
Remedy Mid Tier HIGH 8.8
CVE-2017-17677

BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru…

Mitigation only
Fix from $1,950 2021-05-19
Remedy Mid Tier MEDIUM 6.1
CVE-2017-17678

BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utili…

No fix yet
Fix from $1,600 2021-05-19
Remedy Mid Tier MEDIUM 5.3
CVE-2017-17675

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack …

Mitigation only
Fix from $1,600 2021-05-19
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5071

AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"…

No fix yet
Fix from $1,600 2020-01-15
Remedy Ar System Server MEDIUM 6.5
CVE-2015-5072

The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi…

No fix yet
Fix from $1,600 2020-01-15
Remedy Smart Reporting MEDIUM 6.5
CVE-2019-11216

BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack…

Fix: after 19.02.01
Fix from $1,600 2019-12-04
Patrol Agent HIGH 7.8
CVE-2019-17043

An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat…

Mitigation only
Fix from $1,950 2019-10-14
Patrol Agent HIGH 7.8
CVE-2019-17044

An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" …

Patch available
Fix from $1,950 2019-10-14
Myit Digital Workplace CRITICAL 9.8
CVE-2019-16755

BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-au…

Fix: 18.08.00+
Fix from $2,300 2019-09-26
Remedy Smart Reporting MEDIUM 5.4
CVE-2019-1010147

Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked …

Fix: 7.3+
Fix from $1,600 2019-07-26
Patrol Agent CRITICAL 9.8
CVE-2019-8352EPSS 6%

By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed…

Fix: after 11.3.01
Fix from $2,300 2019-05-20
Remedy Action Request System HIGH 8.8
CVE-2018-18862

BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configura…

No fix yet
Fix from $1,950 2019-03-21
Patrol Agent HIGH 7.8
CVE-2018-20735EPSS 7%

An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalatio…

Fix: after 11.3.01
Fix from $1,950 2019-01-17
Remedy Action Request System Server MEDIUM 6.5
CVE-2018-19505

Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act …

No fix yet
Fix from $1,600 2019-01-03
Remedy Action Request System MEDIUM 6.1
CVE-2015-9257

BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.

Mitigation only
Fix from $1,600 2018-03-24
Remedy Action Request System MEDIUM 5.4
CVE-2017-18228

Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.

Fix: after 9.1
Fix from $1,600 2018-03-12
Remedy Action Request System HIGH 8.1
CVE-2017-18223

BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.

Fix: 9.1.03+
Fix from $1,950 2018-03-10
Track It\! CRITICAL 9.8
CVE-2016-6598EPSS 19%

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont…

Fix: after 11.4
Fix from $2,300 2018-01-30
Track It\! CRITICAL 9.8
CVE-2016-6599EPSS 12%

BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service c…

Fix: after 11.4
Fix from $2,300 2018-01-30
Footprints Service Core MEDIUM 6.1
CVE-2014-9514

Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.

No fix yet
Fix from $1,600 2017-08-28
Patrol HIGH 7.8
CVE-2017-13130

mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid roo…

No fix yet
Fix from $1,950 2017-08-23
Server Automation MEDIUM 5.3
CVE-2016-5063EPSS 8%

The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization…

Fix: after 8.7
Fix from $1,600 2017-05-02
Remedy Action Request System HIGH 7.5
CVE-2016-2349

Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.

Mitigation only
Fix from $1,950 2016-12-21
Bladelogic Server Automation Console CRITICAL 9.8
CVE-2016-4322EPSS 5%

BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p…

No fix yet
Fix from $2,300 2016-12-13
Patrol HIGH 7.8
CVE-2016-9638

In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary n…

Fix: after 9.13.10.01
Fix from $1,950 2016-12-02
Bladelogic Server Automation Console HIGH 7.5
CVE-2016-1543EPSS 72%

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attacke…

Patch available
Fix from $1,950 2016-06-13
Bladelogic Server Automation Console HIGH 7.5
CVE-2016-1542EPSS 75%

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers t…

Patch available
Fix from $1,950 2016-06-13
Track It\! MEDIUM 5.0
CVE-2014-8270EPSS 20%

BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy…

Mitigation only
Fix from $1,600 2014-12-12