Skip to content
Noroxi

BMC records

79 published records for vendor bmc.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

79 records
  • BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute

    HighCVSS 7.5WeaponizedEPSS 79%

    bmc · track-it\!Oct 10, 2014

  • The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote at

    HighCVSS 7.5WeaponizedEPSS 75%

    bmc · bladelogic server automation consoleJun 13, 2016

  • The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remot

    HighCVSS 7.5WeaponizedEPSS 72%

    bmc · bladelogic server automation consoleJun 13, 2016

  • BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.

    CriticalCVSS 9.8Proof of conceptEPSS 19%

    bmc · track-it\!Jan 30, 2018

  • BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

    HighCVSS 8.7Proof of conceptEPSS 34%

    bmc · footprintsMar 19, 2026

  • BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    bmc · track-it\!Jan 30, 2018

  • Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers

    CriticalCVSS 10.0No exploitEPSS 8%

    bmc · patrol agentJan 27, 2009

  • Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, a

    CriticalCVSS 10.0No exploitEPSS 7%

    bmc · performance analysis for serversFeb 10, 2011

  • By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network t

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    bmc · patrol agentMay 20, 2019

  • BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary f

    CriticalCVSS 9.8No exploitEPSS 5%

    bmc · bladelogic server automation consoleDec 13, 2016

  • Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

    CriticalCVSS 10.0No exploitEPSS 2%

    bmc · patrol agentApr 1, 1999

  • BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

    CriticalCVSS 10.0No exploitEPSS 2%

    bmc · patrol agentApr 9, 1999

  • BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass

    MediumCVSS 6.9Proof of conceptEPSS 45%

    bmc · footprintsMar 19, 2026

  • BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfo

    CriticalCVSS 9.8No exploitEPSS 3%

    bmc · myit digital workplaceSep 26, 2019

  • BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.

    CriticalCVSS 9.8No exploitEPSS 2%

    bmc · remedy mid-tierMay 19, 2021

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.

    CriticalCVSS 9.8No exploitEPSS 2%

    bmc · track-it\!Aug 3, 2022

  • This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.

    CriticalCVSS 9.8No exploitEPSS 2%

    bmc · track-it\!Feb 18, 2022

  • An issue was discovered in BMC Patrol through 23.1.00.

    CriticalCVSS 9.8No exploitEPSS 1%

    bmc · patrol agentMay 31, 2023

  • A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fie

    CriticalCVSS 9.8No exploitEPSS 1%

    bmc · control-mFeb 25, 2023

  • CVE-2017-9453
    39Monitor

    BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

    CriticalCVSS 9.8No exploitEPSS 1%

    bmc · server automationSep 5, 2023

  • BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    bmc · control-mJul 31, 2023

  • **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.

    CriticalCVSS 9.8No exploitEPSS 1%

    bmc · remedy mid-tierSep 18, 2024

  • An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.

    CriticalCVSS 9.8No exploitEPSS 0%

    bmc · control-m\/managed file transferApr 10, 2026

  • BMC Control-M/Agent default SSL/TLS configuration authenticated bypass

    CriticalCVSS 9.5No exploitEPSS 0%

    bmc · control-m\/agentSep 16, 2025

  • BMC Control-M/Agent unescaped NULL byte in access control list checks

    CriticalCVSS 9.5No exploitEPSS 0%

    bmc · control-m\/agentSep 16, 2025