Vulnerabilities > BMC > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-01-30 CVE-2016-6598 Improper Access Control vulnerability in BMC Track-It! 11.3/11.3.0.355/11.4
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.
network
low complexity
bmc CWE-284
critical
9.8
2016-12-13 CVE-2016-4322 Improper Authentication vulnerability in BMC Bladelogic Server Automation Console 8.7.00
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.
network
low complexity
bmc CWE-287
critical
9.8