BMC records
79 published records for vendor bmc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 5 · 6.3%
- Pre-auth RCE
- 12
- With a fix record
- 2.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-287 Improper Authentication5
- CWE-276 Incorrect Default Permissions4
- CWE-284 Improper Access Control3
- CWE-306 Missing Authentication for Critical Function3
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
79 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2014-4872Weaponized | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute bmc · track-it\! · CWE-306 | High7.5 | — | 79.3% | Oct 10, 2014 |
52Plan | CVE-2016-1542Weaponized | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote atbmc · bladelogic server automation console · CWE-20 | High7.5 | — | 74.6% | Jun 13, 2016 |
52Plan | CVE-2016-1543Weaponized | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remotbmc · bladelogic server automation console · CWE-284 | High7.5 | — | 71.9% | Jun 13, 2016 |
45Plan | CVE-2016-6598Proof of concept | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.bmc · track-it\! · CWE-284 | Critical9.8 | — | 19.2% | Jan 30, 2018 |
44Plan | CVE-2025-71260Proof of concept | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEbmc · footprints · CWE-502 | High8.7 | — | 34.4% | Mar 19, 2026 |
43Plan | CVE-2016-6599Proof of concept | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.bmc · track-it\! · CWE-255 | Critical9.8 | — | 12.3% | Jan 30, 2018 |
42Plan | CVE-2008-5982No exploit | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiersbmc · patrol agent · CWE-134 | Critical10.0 | — | 7.8% | Jan 27, 2009 |
42Plan | CVE-2011-0975No exploit | Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, abmc · performance analysis for servers · CWE-119 | Critical10.0 | — | 6.8% | Feb 10, 2011 |
41Plan | CVE-2019-8352Proof of concept | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network tbmc · patrol agent · CWE-798 | Critical9.8 | — | 6.3% | May 20, 2019 |
41Plan | CVE-2016-4322No exploit | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary fbmc · bladelogic server automation console · CWE-287 | Critical9.8 | — | 5.2% | Dec 13, 2016 |
41Plan | CVE-1999-0443No exploit | Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.bmc · patrol agent | Critical10.0 | — | 2.2% | Apr 1, 1999 |
41Plan | CVE-1999-0801No exploit | BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.bmc · patrol agent | Critical10.0 | — | 2.2% | Apr 9, 1999 |
40Plan | CVE-2025-71257Proof of concept | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassbmc · footprints · CWE-306 | Medium6.9 | — | 44.6% | Mar 19, 2026 |
40Plan | CVE-2019-16755No exploit | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfobmc · myit digital workplace · CWE-502 | Critical9.8 | — | 2.5% | Sep 26, 2019 |
40Plan | CVE-2017-17674No exploit | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.bmc · remedy mid-tier · CWE-918 | Critical9.8 | — | 2.1% | May 19, 2021 |
40Plan | CVE-2022-35865No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.bmc · track-it\! · CWE-306 | Critical9.8 | — | 1.9% | Aug 3, 2022 |
40Plan | CVE-2022-24047No exploit | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.bmc · track-it\! · CWE-288 | Critical9.8 | — | 1.9% | Feb 18, 2022 |
39Monitor | CVE-2023-34257No exploit | An issue was discovered in BMC Patrol through 23.1.00.bmc · patrol agent | Critical9.8 | — | 1.0% | May 31, 2023 |
39Monitor | CVE-2023-26550No exploit | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fiebmc · control-m · CWE-89 | Critical9.8 | — | 0.8% | Feb 25, 2023 |
39Monitor | CVE-2017-9453No exploit | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.bmc · server automation · CWE-863 | Critical9.8 | — | 0.7% | Sep 5, 2023 |
39Monitor | CVE-2023-39122No exploit | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.bmc · control-m · CWE-89 | Critical9.8 | — | 0.7% | Jul 31, 2023 |
39Monitor | CVE-2024-34399No exploit | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.bmc · remedy mid-tier · CWE-287 | Critical9.8 | — | 0.5% | Sep 18, 2024 |
39Monitor | CVE-2026-23781No exploit | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.bmc · control-m\/managed file transfer · CWE-798 | Critical9.8 | — | 0.3% | Apr 10, 2026 |
38Monitor | CVE-2025-55109No exploit | BMC Control-M/Agent default SSL/TLS configuration authenticated bypassbmc · control-m\/agent · CWE-295 | Critical9.5 | — | 0.4% | Sep 16, 2025 |
38Monitor | CVE-2025-55113No exploit | BMC Control-M/Agent unescaped NULL byte in access control list checksbmc · control-m\/agent · CWE-158 | Critical9.5 | — | 0.3% | Sep 16, 2025 |
- CVE-2014-487254Plan
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute
HighCVSS 7.5WeaponizedEPSS 79%bmc · track-it\!Oct 10, 2014
- CVE-2016-154252Plan
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote at
HighCVSS 7.5WeaponizedEPSS 75%bmc · bladelogic server automation consoleJun 13, 2016
- CVE-2016-154352Plan
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remot
HighCVSS 7.5WeaponizedEPSS 72%bmc · bladelogic server automation consoleJun 13, 2016
- CVE-2016-659845Plan
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.
CriticalCVSS 9.8Proof of conceptEPSS 19%bmc · track-it\!Jan 30, 2018
- CVE-2025-7126044Plan
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
HighCVSS 8.7Proof of conceptEPSS 34%bmc · footprintsMar 19, 2026
- CVE-2016-659943Plan
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.
CriticalCVSS 9.8Proof of conceptEPSS 12%bmc · track-it\!Jan 30, 2018
- CVE-2008-598242Plan
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers
CriticalCVSS 10.0No exploitEPSS 8%bmc · patrol agentJan 27, 2009
- CVE-2011-097542Plan
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, a
CriticalCVSS 10.0No exploitEPSS 7%bmc · performance analysis for serversFeb 10, 2011
- CVE-2019-835241Plan
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network t
CriticalCVSS 9.8Proof of conceptEPSS 6%bmc · patrol agentMay 20, 2019
- CVE-2016-432241Plan
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary f
CriticalCVSS 9.8No exploitEPSS 5%bmc · bladelogic server automation consoleDec 13, 2016
- CVE-1999-044341Plan
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
CriticalCVSS 10.0No exploitEPSS 2%bmc · patrol agentApr 1, 1999
- CVE-1999-080141Plan
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
CriticalCVSS 10.0No exploitEPSS 2%bmc · patrol agentApr 9, 1999
- CVE-2025-7125740Plan
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
MediumCVSS 6.9Proof of conceptEPSS 45%bmc · footprintsMar 19, 2026
- CVE-2019-1675540Plan
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfo
CriticalCVSS 9.8No exploitEPSS 3%bmc · myit digital workplaceSep 26, 2019
- CVE-2017-1767440Plan
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.
CriticalCVSS 9.8No exploitEPSS 2%bmc · remedy mid-tierMay 19, 2021
- CVE-2022-3586540Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.
CriticalCVSS 9.8No exploitEPSS 2%bmc · track-it\!Aug 3, 2022
- CVE-2022-2404740Plan
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.
CriticalCVSS 9.8No exploitEPSS 2%bmc · track-it\!Feb 18, 2022
- CVE-2023-3425739Monitor
An issue was discovered in BMC Patrol through 23.1.00.
CriticalCVSS 9.8No exploitEPSS 1%bmc · patrol agentMay 31, 2023
- CVE-2023-2655039Monitor
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fie
CriticalCVSS 9.8No exploitEPSS 1%bmc · control-mFeb 25, 2023
- CVE-2017-945339Monitor
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
CriticalCVSS 9.8No exploitEPSS 1%bmc · server automationSep 5, 2023
- CVE-2023-3912239Monitor
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.
CriticalCVSS 9.8No exploitEPSS 1%bmc · control-mJul 31, 2023
- CVE-2024-3439939Monitor
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.
CriticalCVSS 9.8No exploitEPSS 1%bmc · remedy mid-tierSep 18, 2024
- CVE-2026-2378139Monitor
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.
CriticalCVSS 9.8No exploitEPSS 0%bmc · control-m\/managed file transferApr 10, 2026
- CVE-2025-5510938Monitor
BMC Control-M/Agent default SSL/TLS configuration authenticated bypass
CriticalCVSS 9.5No exploitEPSS 0%bmc · control-m\/agentSep 16, 2025
- CVE-2025-5511338Monitor
BMC Control-M/Agent unescaped NULL byte in access control list checks
CriticalCVSS 9.5No exploitEPSS 0%bmc · control-m\/agentSep 16, 2025