Записи BMC
79 опубликованных записей вендора bmc.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 6,3 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 2,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-287 Improper Authentication5
- CWE-276 Incorrect Default Permissions4
- CWE-284 Improper Access Control3
- CWE-306 Missing Authentication for Critical Function3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
79 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2014-4872Готовый эксплойт | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute bmc · track-it\! · CWE-306 | Высокая7,5 | — | 79,3 % | 10 окт. 2014 г. |
52В плане | CVE-2016-1542Готовый эксплойт | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote atbmc · bladelogic server automation console · CWE-20 | Высокая7,5 | — | 74,6 % | 13 июн. 2016 г. |
52В плане | CVE-2016-1543Готовый эксплойт | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remotbmc · bladelogic server automation console · CWE-284 | Высокая7,5 | — | 71,9 % | 13 июн. 2016 г. |
45В плане | CVE-2016-6598Proof of concept | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.bmc · track-it\! · CWE-284 | Критическая9,8 | — | 19,2 % | 30 янв. 2018 г. |
44В плане | CVE-2025-71260Proof of concept | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEbmc · footprints · CWE-502 | Высокая8,7 | — | 34,4 % | 19 мар. 2026 г. |
43В плане | CVE-2016-6599Proof of concept | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.bmc · track-it\! · CWE-255 | Критическая9,8 | — | 12,3 % | 30 янв. 2018 г. |
42В плане | CVE-2008-5982Эксплойта нет | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiersbmc · patrol agent · CWE-134 | Критическая10,0 | — | 7,8 % | 27 янв. 2009 г. |
42В плане | CVE-2011-0975Эксплойта нет | Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, abmc · performance analysis for servers · CWE-119 | Критическая10,0 | — | 6,8 % | 10 февр. 2011 г. |
41В плане | CVE-2019-8352Proof of concept | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network tbmc · patrol agent · CWE-798 | Критическая9,8 | — | 6,3 % | 20 мая 2019 г. |
41В плане | CVE-2016-4322Эксплойта нет | BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary fbmc · bladelogic server automation console · CWE-287 | Критическая9,8 | — | 5,2 % | 13 дек. 2016 г. |
41В плане | CVE-1999-0443Эксплойта нет | Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.bmc · patrol agent | Критическая10,0 | — | 2,2 % | 1 апр. 1999 г. |
41В плане | CVE-1999-0801Эксплойта нет | BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.bmc · patrol agent | Критическая10,0 | — | 2,2 % | 9 апр. 1999 г. |
40В плане | CVE-2025-71257Proof of concept | BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypassbmc · footprints · CWE-306 | Средняя6,9 | — | 44,6 % | 19 мар. 2026 г. |
40В плане | CVE-2019-16755Эксплойта нет | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfobmc · myit digital workplace · CWE-502 | Критическая9,8 | — | 2,5 % | 26 сент. 2019 г. |
40В плане | CVE-2017-17674Эксплойта нет | BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.bmc · remedy mid-tier · CWE-918 | Критическая9,8 | — | 2,1 % | 19 мая 2021 г. |
40В плане | CVE-2022-35865Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.bmc · track-it\! · CWE-306 | Критическая9,8 | — | 1,9 % | 3 авг. 2022 г. |
40В плане | CVE-2022-24047Эксплойта нет | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.bmc · track-it\! · CWE-288 | Критическая9,8 | — | 1,9 % | 18 февр. 2022 г. |
39Наблюдать | CVE-2023-34257Эксплойта нет | An issue was discovered in BMC Patrol through 23.1.00.bmc · patrol agent | Критическая9,8 | — | 1,0 % | 31 мая 2023 г. |
39Наблюдать | CVE-2023-26550Эксплойта нет | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fiebmc · control-m · CWE-89 | Критическая9,8 | — | 0,8 % | 25 февр. 2023 г. |
39Наблюдать | CVE-2017-9453Эксплойта нет | BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.bmc · server automation · CWE-863 | Критическая9,8 | — | 0,7 % | 5 сент. 2023 г. |
39Наблюдать | CVE-2023-39122Эксплойта нет | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.bmc · control-m · CWE-89 | Критическая9,8 | — | 0,7 % | 31 июл. 2023 г. |
39Наблюдать | CVE-2024-34399Эксплойта нет | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.bmc · remedy mid-tier · CWE-287 | Критическая9,8 | — | 0,5 % | 18 сент. 2024 г. |
39Наблюдать | CVE-2026-23781Эксплойта нет | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.bmc · control-m\/managed file transfer · CWE-798 | Критическая9,8 | — | 0,3 % | 10 апр. 2026 г. |
38Наблюдать | CVE-2025-55109Эксплойта нет | BMC Control-M/Agent default SSL/TLS configuration authenticated bypassbmc · control-m\/agent · CWE-295 | Критическая9,5 | — | 0,4 % | 16 сент. 2025 г. |
38Наблюдать | CVE-2025-55113Эксплойта нет | BMC Control-M/Agent unescaped NULL byte in access control list checksbmc · control-m\/agent · CWE-158 | Критическая9,5 | — | 0,3 % | 16 сент. 2025 г. |
- CVE-2014-487254В плане
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %bmc · track-it\!10 окт. 2014 г.
- CVE-2016-154252В плане
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote at
ВысокаяCVSS 7,5Готовый эксплойтEPSS 75 %bmc · bladelogic server automation console13 июн. 2016 г.
- CVE-2016-154352В плане
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remot
ВысокаяCVSS 7,5Готовый эксплойтEPSS 72 %bmc · bladelogic server automation console13 июн. 2016 г.
- CVE-2016-659845В плане
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.
КритическаяCVSS 9,8Proof of conceptEPSS 19 %bmc · track-it\!30 янв. 2018 г.
- CVE-2025-7126044В плане
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE
ВысокаяCVSS 8,7Proof of conceptEPSS 34 %bmc · footprints19 мар. 2026 г.
- CVE-2016-659943В плане
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.
КритическаяCVSS 9,8Proof of conceptEPSS 12 %bmc · track-it\!30 янв. 2018 г.
- CVE-2008-598242В плане
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %bmc · patrol agent27 янв. 2009 г.
- CVE-2011-097542В плане
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, a
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %bmc · performance analysis for servers10 февр. 2011 г.
- CVE-2019-835241В плане
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network t
КритическаяCVSS 9,8Proof of conceptEPSS 6 %bmc · patrol agent20 мая 2019 г.
- CVE-2016-432241В плане
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary f
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %bmc · bladelogic server automation console13 дек. 2016 г.
- CVE-1999-044341В плане
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %bmc · patrol agent1 апр. 1999 г.
- CVE-1999-080141В плане
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %bmc · patrol agent9 апр. 1999 г.
- CVE-2025-7125740В плане
BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass
СредняяCVSS 6,9Proof of conceptEPSS 45 %bmc · footprints19 мар. 2026 г.
- CVE-2019-1675540В плане
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfo
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %bmc · myit digital workplace26 сент. 2019 г.
- CVE-2017-1767440В плане
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bmc · remedy mid-tier19 мая 2021 г.
- CVE-2022-3586540В плане
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bmc · track-it\!3 авг. 2022 г.
- CVE-2022-2404740В плане
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bmc · track-it\!18 февр. 2022 г.
- CVE-2023-3425739Наблюдать
An issue was discovered in BMC Patrol through 23.1.00.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmc · patrol agent31 мая 2023 г.
- CVE-2023-2655039Наблюдать
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fie
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmc · control-m25 февр. 2023 г.
- CVE-2017-945339Наблюдать
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmc · server automation5 сент. 2023 г.
- CVE-2023-3912239Наблюдать
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmc · control-m31 июл. 2023 г.
- CVE-2024-3439939Наблюдать
**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %bmc · remedy mid-tier18 сент. 2024 г.
- CVE-2026-2378139Наблюдать
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %bmc · control-m\/managed file transfer10 апр. 2026 г.
- CVE-2025-5510938Наблюдать
BMC Control-M/Agent default SSL/TLS configuration authenticated bypass
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %bmc · control-m\/agent16 сент. 2025 г.
- CVE-2025-5511338Наблюдать
BMC Control-M/Agent unescaped NULL byte in access control list checks
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %bmc · control-m\/agent16 сент. 2025 г.