Vulnerability index

Browse CVEs

75 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-24047 This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re… Track It\! Mitigation only Fix from $2,3002022-02-18 CRITICAL 9.8 CVE-2017-17674 BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be… Remedy Mid Tier Mitigation only Fix from $2,3002021-05-19 HIGH 8.8 CVE-2017-17677 BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to ru… Remedy Mid Tier Mitigation only Fix from $1,9502021-05-19 MEDIUM 6.1 CVE-2017-17678 BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utili… Remedy Mid Tier No fix yet Fix from $1,6002021-05-19 MEDIUM 5.3 CVE-2017-17675 BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack … Remedy Mid Tier Mitigation only Fix from $1,6002021-05-19 MEDIUM 6.5 CVE-2015-5071 AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate"… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 MEDIUM 6.5 CVE-2015-5072 The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navi… Remedy Ar System Server No fix yet Fix from $1,6002020-01-15 MEDIUM 6.5 CVE-2019-11216 BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack… Remedy Smart Reporting after 19.02.01 Fix from $1,6002019-12-04 HIGH 7.8 CVE-2019-17043 An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevat… Patrol Agent Mitigation only Fix from $1,9502019-10-14 HIGH 7.8 CVE-2019-17044 An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" … Patrol Agent Patch available Fix from $1,9502019-10-14 CRITICAL 9.8 CVE-2019-16755 BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-au… Myit Digital Workplace 18.08.00+ Fix from $2,3002019-09-26 MEDIUM 5.4 CVE-2019-1010147 Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked … Remedy Smart Reporting 7.3+ Fix from $1,6002019-07-26 CRITICAL 9.8 CVE-2019-8352EPSS 6% By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed… Patrol Agent after 11.3.01 Fix from $2,3002019-05-20 HIGH 8.8 CVE-2018-18862 BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configura… Remedy Action Request System No fix yet Fix from $1,9502019-03-21 HIGH 7.8 CVE-2018-20735EPSS 7% An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalatio… Patrol Agent after 11.3.01 Fix from $1,9502019-01-17 MEDIUM 6.5 CVE-2018-19505 Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act … Remedy Action Request System Server No fix yet Fix from $1,6002019-01-03 MEDIUM 6.1 CVE-2015-9257 BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS. Remedy Action Request System Mitigation only Fix from $1,6002018-03-24 MEDIUM 5.4 CVE-2017-18228 Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request. Remedy Action Request System after 9.1 Fix from $1,6002018-03-12 HIGH 8.1 CVE-2017-18223 BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access. Remedy Action Request System 9.1.03+ Fix from $1,9502018-03-10 CRITICAL 9.8 CVE-2016-6598EPSS 19% BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont… Track It\! after 11.4 Fix from $2,3002018-01-30 CRITICAL 9.8 CVE-2016-6599EPSS 12% BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service c… Track It\! after 11.4 Fix from $2,3002018-01-30 MEDIUM 6.1 CVE-2014-9514 Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5. Footprints Service Core No fix yet Fix from $1,6002017-08-28 HIGH 7.8 CVE-2017-13130 mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid roo… Patrol No fix yet Fix from $1,9502017-08-23 MEDIUM 5.3 CVE-2016-5063EPSS 8% The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization… Server Automation after 8.7 Fix from $1,6002017-05-02 HIGH 7.5 CVE-2016-2349 Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password. Remedy Action Request System Mitigation only Fix from $1,9502016-12-21 CRITICAL 9.8 CVE-2016-4322EPSS 5% BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or p… Bladelogic Server Automation Console No fix yet Fix from $2,3002016-12-13 HIGH 7.8 CVE-2016-9638 In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary n… Patrol after 9.13.10.01 Fix from $1,9502016-12-02 HIGH 7.5 CVE-2016-1543EPSS 72% The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attacke… Bladelogic Server Automation Console Patch available Fix from $1,9502016-06-13 HIGH 7.5 CVE-2016-1542EPSS 75% The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers t… Bladelogic Server Automation Console Patch available Fix from $1,9502016-06-13 MEDIUM 5.0 CVE-2014-8270EPSS 20% BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy… Track It\! Mitigation only Fix from $1,6002014-12-12