Vulnerability index

Browse CVEs

75 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control M\/managed File Transfer CRITICAL 9.8
CVE-2026-23781

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the appl…

Fix: after 9.0.22
Fix from $2,300 2026-04-10
Control M\/managed File Transfer HIGH 8.8
CVE-2026-23780

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenti…

Fix: after 9.0.22
Fix from $1,950 2026-04-10
Control M\/managed File Transfer HIGH 7.5
CVE-2026-23782

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API ide…

Fix: after 9.0.22
Fix from $1,950 2026-04-10
Footprints HIGH 8.8
CVE-2025-71260EPSS 34%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTA…

Fix: after 20.24.01.001
Fix from $1,950 2026-03-19
Footprints HIGH 7.1
CVE-2025-71258EPSS 17%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component t…

Fix: after 20.24.01.001
Fix from $1,950 2026-03-19
Footprints HIGH 7.1
CVE-2025-71259EPSS 13%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API comp…

Fix: after 20.24.01.001
Fix from $1,950 2026-03-19
Footprints CRITICAL 9.1
CVE-2025-71257EPSS 5%

BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to improper enforcement of security fil…

Fix: after 20.24.01.001
Fix from $2,300 2026-03-19
Control M\/agent MEDIUM 5.3
CVE-2025-55117

A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configu…

Fix: after 9.0.22
Fix from $1,600 2025-09-16
Control M\/agent HIGH 8.8
CVE-2025-55115

A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vu…

Fix: 9.0.20.100+
Fix from $1,950 2025-09-16
Control M\/agent HIGH 8.8
CVE-2025-55116

A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This …

Fix: 9.0.20.100+
Fix from $1,950 2025-09-16
Control M\/agent CRITICAL 10.0
CVE-2025-55113

If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 t…

Fix: after 9.0.22
Fix from $2,300 2025-09-16
Control M\/agent HIGH 7.4
CVE-2025-55112

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Bl…

Fix: after 9.0.20.200
Fix from $1,950 2025-09-16
Control M\/agent MEDIUM 5.5
CVE-2025-55111

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earl…

Fix: 9.0.21+
Fix from $1,600 2025-09-16
Control M\/agent CRITICAL 9.0
CVE-2025-55109

An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported ver…

Fix: after 9.0.22
Fix from $2,300 2025-09-16
Control M\/server HIGH 7.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …

Mitigation only
Fix from $1,950 2025-08-07
Remedy Mid Tier CRITICAL 9.8
CVE-2024-34399

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user ac…

Mitigation only
Fix from $2,300 2024-09-18
Track It\! HIGH 8.8
CVE-2021-35002

BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…

Mitigation only
Fix from $1,950 2024-05-07
Track It\! MEDIUM 6.5
CVE-2021-35001

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…

Mitigation only
Fix from $1,600 2024-05-07
Control M HIGH 7.8
CVE-2024-1605

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissi…

Fix: 9.0.20.238 / 9.0.21.201+
Fix from $1,950 2024-03-18
Control M MEDIUM 5.4
CVE-2024-1606

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection…

Fix: 9.0.20.238 / 9.0.21.201+
Fix from $1,600 2024-03-18
Control M MEDIUM 6.8
CVE-2024-1604

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and ma…

Fix: 9.0.20.238 / 9.0.21.201+
Fix from $1,600 2024-03-18
Patrol Agent HIGH 7.8
CVE-2020-35593

BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

Fix: after 20.08.00
Fix from $1,950 2023-09-05
Server Automation CRITICAL 9.8
CVE-2017-9453

BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

Fix: after 8.9.01
Fix from $2,300 2023-09-05
Control M CRITICAL 9.8
CVE-2023-39122

BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is als…

Fix: 9.0.21+
Fix from $2,300 2023-07-31
Patrol Agent CRITICAL 9.8
CVE-2023-34257

An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not req…

Fix: after 23.1.00
Fix from $2,300 2023-05-31
Patrol HIGH 7.5
CVE-2023-34258

An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol accou…

Fix: 22.1.00+
Fix from $1,950 2023-05-31
Control M CRITICAL 9.8
CVE-2023-26550

A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.

Fix: 9.0.20.214+
Fix from $2,300 2023-02-25
Remedy It Service Management Suite MEDIUM 5.4
CVE-2022-26088

An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF …

No fix yet
Fix from $1,600 2022-11-10
Track It\! CRITICAL 9.8
CVE-2022-35865

This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…

Patch available
Fix from $2,300 2022-08-03
Track It\! MEDIUM 6.5
CVE-2022-35864

This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication …

Patch available
Fix from $1,600 2022-08-03