BMC kayıtları
bmc üreticisine ait 79 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %6,3
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %2,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-287 Improper Authentication5
- CWE-276 Incorrect Default Permissions4
- CWE-284 Improper Access Control3
- CWE-306 Missing Authentication for Critical Function3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
79 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2014-4872Silahlaştırılmış | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute bmc · track-it\! · CWE-306 | Yüksek7,5 | — | %79,3 | 10 Eki 2014 |
52Planlayın | CVE-2016-1542Silahlaştırılmış | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote atbmc · bladelogic server automation console · CWE-20 | Yüksek7,5 | — | %74,6 | 13 Haz 2016 |
52Planlayın | CVE-2016-1543Silahlaştırılmış | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remotbmc · bladelogic server automation console · CWE-284 | Yüksek7,5 | — | %71,9 | 13 Haz 2016 |
45Planlayın | CVE-2016-6598Kavram kanıtı | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.bmc · track-it\! · CWE-284 | Kritik9,8 | — | %19,2 | 30 Oca 2018 |
44Planlayın | CVE-2025-71260Kavram kanıtı | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEbmc · footprints · CWE-502 | Yüksek8,7 | — | %34,4 | 19 Mar 2026 |
43Planlayın | CVE-2016-6599Kavram kanıtı | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.bmc · track-it\! · CWE-255 | Kritik9,8 | — | %12,3 | 30 Oca 2018 |
42Planlayın | CVE-2008-5982İstismar yok | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiersbmc · patrol agent · CWE-134 | Kritik10,0 | — | %7,8 | 27 Oca 2009 |
42Planlayın | CVE-2011-0975İstismar yok | Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, abmc · performance analysis for servers · CWE-119 | Kritik10,0 | — | %6,8 | 10 Şub 2011 |
41Planlayın | CVE-2019-8352Kavram kanıtı | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network tbmc · patrol agent · CWE-798 | Kritik9,8 | — | %6,3 | 20 May 2019 |
41Planlayın | CVE-2016-4322İstismar yok | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary fbmc · bladelogic server automation console · CWE-287 | Kritik9,8 | — | %5,2 | 13 Ara 2016 |
41Planlayın | CVE-1999-0443İstismar yok | Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.bmc · patrol agent | Kritik10,0 | — | %2,2 | 1 Nis 1999 |
41Planlayın | CVE-1999-0801İstismar yok | BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.bmc · patrol agent | Kritik10,0 | — | %2,2 | 9 Nis 1999 |
40Planlayın | CVE-2025-71257Kavram kanıtı | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassbmc · footprints · CWE-306 | Orta6,9 | — | %44,6 | 19 Mar 2026 |
40Planlayın | CVE-2019-16755İstismar yok | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfobmc · myit digital workplace · CWE-502 | Kritik9,8 | — | %2,5 | 26 Eyl 2019 |
40Planlayın | CVE-2017-17674İstismar yok | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.bmc · remedy mid-tier · CWE-918 | Kritik9,8 | — | %2,1 | 19 May 2021 |
40Planlayın | CVE-2022-35865İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.bmc · track-it\! · CWE-306 | Kritik9,8 | — | %1,9 | 3 Ağu 2022 |
40Planlayın | CVE-2022-24047İstismar yok | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.bmc · track-it\! · CWE-288 | Kritik9,8 | — | %1,9 | 18 Şub 2022 |
39İzleyin | CVE-2023-34257İstismar yok | An issue was discovered in BMC Patrol through 23.1.00.bmc · patrol agent | Kritik9,8 | — | %1,0 | 31 May 2023 |
39İzleyin | CVE-2023-26550İstismar yok | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fiebmc · control-m · CWE-89 | Kritik9,8 | — | %0,8 | 25 Şub 2023 |
39İzleyin | CVE-2017-9453İstismar yok | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.bmc · server automation · CWE-863 | Kritik9,8 | — | %0,7 | 5 Eyl 2023 |
39İzleyin | CVE-2023-39122İstismar yok | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.bmc · control-m · CWE-89 | Kritik9,8 | — | %0,7 | 31 Tem 2023 |
39İzleyin | CVE-2024-34399İstismar yok | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.bmc · remedy mid-tier · CWE-287 | Kritik9,8 | — | %0,5 | 18 Eyl 2024 |
39İzleyin | CVE-2026-23781İstismar yok | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.bmc · control-m\/managed file transfer · CWE-798 | Kritik9,8 | — | %0,3 | 10 Nis 2026 |
38İzleyin | CVE-2025-55109İstismar yok | BMC Control-M/Agent default SSL/TLS configuration authenticated bypassbmc · control-m\/agent · CWE-295 | Kritik9,5 | — | %0,4 | 16 Eyl 2025 |
38İzleyin | CVE-2025-55113İstismar yok | BMC Control-M/Agent unescaped NULL byte in access control list checksbmc · control-m\/agent · CWE-158 | Kritik9,5 | — | %0,3 | 16 Eyl 2025 |
- CVE-2014-487254Planlayın
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute
YüksekCVSS 7,5SilahlaştırılmışEPSS %79bmc · track-it\!10 Eki 2014
- CVE-2016-154252Planlayın
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote at
YüksekCVSS 7,5SilahlaştırılmışEPSS %75bmc · bladelogic server automation console13 Haz 2016
- CVE-2016-154352Planlayın
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remot
YüksekCVSS 7,5SilahlaştırılmışEPSS %72bmc · bladelogic server automation console13 Haz 2016
- CVE-2016-659845Planlayın
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.
KritikCVSS 9,8Kavram kanıtıEPSS %19bmc · track-it\!30 Oca 2018
- CVE-2025-7126044Planlayın
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
YüksekCVSS 8,7Kavram kanıtıEPSS %34bmc · footprints19 Mar 2026
- CVE-2016-659943Planlayın
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.
KritikCVSS 9,8Kavram kanıtıEPSS %12bmc · track-it\!30 Oca 2018
- CVE-2008-598242Planlayın
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers
KritikCVSS 10,0İstismar yokEPSS %8bmc · patrol agent27 Oca 2009
- CVE-2011-097542Planlayın
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, a
KritikCVSS 10,0İstismar yokEPSS %7bmc · performance analysis for servers10 Şub 2011
- CVE-2019-835241Planlayın
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network t
KritikCVSS 9,8Kavram kanıtıEPSS %6bmc · patrol agent20 May 2019
- CVE-2016-432241Planlayın
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary f
KritikCVSS 9,8İstismar yokEPSS %5bmc · bladelogic server automation console13 Ara 2016
- CVE-1999-044341Planlayın
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
KritikCVSS 10,0İstismar yokEPSS %2bmc · patrol agent1 Nis 1999
- CVE-1999-080141Planlayın
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
KritikCVSS 10,0İstismar yokEPSS %2bmc · patrol agent9 Nis 1999
- CVE-2025-7125740Planlayın
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
OrtaCVSS 6,9Kavram kanıtıEPSS %45bmc · footprints19 Mar 2026
- CVE-2019-1675540Planlayın
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfo
KritikCVSS 9,8İstismar yokEPSS %3bmc · myit digital workplace26 Eyl 2019
- CVE-2017-1767440Planlayın
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.
KritikCVSS 9,8İstismar yokEPSS %2bmc · remedy mid-tier19 May 2021
- CVE-2022-3586540Planlayın
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.
KritikCVSS 9,8İstismar yokEPSS %2bmc · track-it\!3 Ağu 2022
- CVE-2022-2404740Planlayın
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.
KritikCVSS 9,8İstismar yokEPSS %2bmc · track-it\!18 Şub 2022
- CVE-2023-3425739İzleyin
An issue was discovered in BMC Patrol through 23.1.00.
KritikCVSS 9,8İstismar yokEPSS %1bmc · patrol agent31 May 2023
- CVE-2023-2655039İzleyin
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fie
KritikCVSS 9,8İstismar yokEPSS %1bmc · control-m25 Şub 2023
- CVE-2017-945339İzleyin
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
KritikCVSS 9,8İstismar yokEPSS %1bmc · server automation5 Eyl 2023
- CVE-2023-3912239İzleyin
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.
KritikCVSS 9,8İstismar yokEPSS %1bmc · control-m31 Tem 2023
- CVE-2024-3439939İzleyin
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.
KritikCVSS 9,8İstismar yokEPSS %1bmc · remedy mid-tier18 Eyl 2024
- CVE-2026-2378139İzleyin
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.
KritikCVSS 9,8İstismar yokEPSS %0bmc · control-m\/managed file transfer10 Nis 2026
- CVE-2025-5510938İzleyin
BMC Control-M/Agent default SSL/TLS configuration authenticated bypass
KritikCVSS 9,5İstismar yokEPSS %0bmc · control-m\/agent16 Eyl 2025
- CVE-2025-5511338İzleyin
BMC Control-M/Agent unescaped NULL byte in access control list checks
KritikCVSS 9,5İstismar yokEPSS %0bmc · control-m\/agent16 Eyl 2025