Vulnerabilities > BMC
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-25 | CVE-2023-26550 | SQL Injection vulnerability in BMC Control-M A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. | 9.8 |
2022-11-10 | CVE-2022-26088 | Cross-site Scripting vulnerability in BMC Remedy IT Service Management Suite 20.02 An issue was discovered in BMC Remedy before 22.1. | 5.4 |
2022-02-18 | CVE-2022-24047 | Improper Authentication vulnerability in BMC Track-It! 20.21.01.102 This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. | 7.5 |
2021-05-19 | CVE-2017-17674 | Server-Side Request Forgery (SSRF) vulnerability in BMC Remedy Mid-Tier 9.1 BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. | 7.5 |
2021-05-19 | CVE-2017-17675 | Information Exposure Through Log Files vulnerability in BMC Remedy Mid-Tier 9.1 BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. | 5.0 |
2021-05-19 | CVE-2017-17677 | Incorrect Permission Assignment for Critical Resource vulnerability in BMC Remedy Mid-Tier 9.1 BMC Remedy 9.1SP3 is affected by authenticated code execution. | 6.5 |
2021-05-19 | CVE-2017-17678 | Cross-site Scripting vulnerability in BMC Remedy Mid-Tier 9.1 BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). | 4.3 |
2020-01-15 | CVE-2015-5072 | Improper Privilege Management vulnerability in BMC Remedy AR System Server 8.0/9.0 The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter. | 4.0 |
2020-01-15 | CVE-2015-5071 | Improper Privilege Management vulnerability in BMC Remedy AR System Server 8.0/9.0 AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer servlet. | 4.0 |
2019-12-04 | CVE-2019-11216 | Unrestricted Upload of File with Dangerous Type vulnerability in BMC Remedy Smart Reporting BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. | 5.5 |