Vulnerability index

Browse CVEs

75 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-23781 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl… Control M\/managed File Transfer after 9.0.22 Fix from $2,3002026-04-10 HIGH 8.8 CVE-2026-23780 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenti… Control M\/managed File Transfer after 9.0.22 Fix from $1,9502026-04-10 HIGH 7.5 CVE-2026-23782 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API ide… Control M\/managed File Transfer after 9.0.22 Fix from $1,9502026-04-10 HIGH 8.8 CVE-2025-71260EPSS 34% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTA… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-71258EPSS 17% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component t… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 HIGH 7.1 CVE-2025-71259EPSS 13% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API comp… Footprints after 20.24.01.001 Fix from $1,9502026-03-19 CRITICAL 9.1 CVE-2025-71257EPSS 5% BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil… Footprints after 20.24.01.001 Fix from $2,3002026-03-19 MEDIUM 5.3 CVE-2025-55117 A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configu… Control M\/agent after 9.0.22 Fix from $1,6002025-09-16 HIGH 8.8 CVE-2025-55115 A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vu… Control M\/agent 9.0.20.100+ Fix from $1,9502025-09-16 HIGH 8.8 CVE-2025-55116 A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This … Control M\/agent 9.0.20.100+ Fix from $1,9502025-09-16 CRITICAL 10.0 CVE-2025-55113 If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 t… Control M\/agent after 9.0.22 Fix from $2,3002025-09-16 HIGH 7.4 CVE-2025-55112 Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Bl… Control M\/agent after 9.0.20.200 Fix from $1,9502025-09-16 MEDIUM 5.5 CVE-2025-55111 Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earl… Control M\/agent 9.0.21+ Fix from $1,6002025-09-16 CRITICAL 9.0 CVE-2025-55109 An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported ver… Control M\/agent after 9.0.22 Fix from $2,3002025-09-16 HIGH 7.8 CVE-2025-48709 BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could … Control M\/server Mitigation only Fix from $1,9502025-08-07 CRITICAL 9.8 CVE-2024-34399 **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac… Remedy Mid Tier Mitigation only Fix from $2,3002024-09-18 HIGH 8.8 CVE-2021-35002 BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a… Track It\! Mitigation only Fix from $1,9502024-05-07 MEDIUM 6.5 CVE-2021-35001 BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in… Track It\! Mitigation only Fix from $1,6002024-05-07 HIGH 7.8 CVE-2024-1605 BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi… Control M 9.0.20.238 / 9.0.21.201+ Fix from $1,9502024-03-18 MEDIUM 5.4 CVE-2024-1606 Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection… Control M 9.0.20.238 / 9.0.21.201+ Fix from $1,6002024-03-18 MEDIUM 6.8 CVE-2024-1604 Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma… Control M 9.0.20.238 / 9.0.21.201+ Fix from $1,6002024-03-18 HIGH 7.8 CVE-2020-35593 BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host. Patrol Agent after 20.08.00 Fix from $1,9502023-09-05 CRITICAL 9.8 CVE-2017-9453 BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass. Server Automation after 8.9.01 Fix from $2,3002023-09-05 CRITICAL 9.8 CVE-2023-39122 BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is als… Control M 9.0.21+ Fix from $2,3002023-07-31 CRITICAL 9.8 CVE-2023-34257 An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not req… Patrol Agent after 23.1.00 Fix from $2,3002023-05-31 HIGH 7.5 CVE-2023-34258 An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol accou… Patrol 22.1.00+ Fix from $1,9502023-05-31 CRITICAL 9.8 CVE-2023-26550 A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. Control M 9.0.20.214+ Fix from $2,3002023-02-25 MEDIUM 5.4 CVE-2022-26088 An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF … Remedy It Service Management Suite No fix yet Fix from $1,6002022-11-10 CRITICAL 9.8 CVE-2022-35865 This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re… Track It\! Patch available Fix from $2,3002022-08-03 MEDIUM 6.5 CVE-2022-35864 This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication … Track It\! Patch available Fix from $1,6002022-08-03