İçeriğe atla
Noroxi

BMC kayıtları

bmc üreticisine ait 79 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
5 · %6,3
Pre-auth RCE
12
Düzeltme kaydı olan
%2,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

79 kayıt
  • CVE-2014-4872
    54Planlayın

    BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute

    YüksekCVSS 7,5SilahlaştırılmışEPSS %79

    bmc · track-it\!10 Eki 2014

  • CVE-2016-1542
    52Planlayın

    The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote at

    YüksekCVSS 7,5SilahlaştırılmışEPSS %75

    bmc · bladelogic server automation console13 Haz 2016

  • CVE-2016-1543
    52Planlayın

    The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remot

    YüksekCVSS 7,5SilahlaştırılmışEPSS %72

    bmc · bladelogic server automation console13 Haz 2016

  • CVE-2016-6598
    45Planlayın

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010.

    KritikCVSS 9,8Kavram kanıtıEPSS %19

    bmc · track-it\!30 Oca 2018

  • CVE-2025-71260
    44Planlayın

    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCE

    YüksekCVSS 8,7Kavram kanıtıEPSS %34

    bmc · footprints19 Mar 2026

  • CVE-2016-6599
    43Planlayın

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.

    KritikCVSS 9,8Kavram kanıtıEPSS %12

    bmc · track-it\!30 Oca 2018

  • CVE-2008-5982
    42Planlayın

    Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers

    KritikCVSS 10,0İstismar yokEPSS %8

    bmc · patrol agent27 Oca 2009

  • CVE-2011-0975
    42Planlayın

    Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, a

    KritikCVSS 10,0İstismar yokEPSS %7

    bmc · performance analysis for servers10 Şub 2011

  • CVE-2019-8352
    41Planlayın

    By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network t

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    bmc · patrol agent20 May 2019

  • CVE-2016-4322
    41Planlayın

    BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary f

    KritikCVSS 9,8İstismar yokEPSS %5

    bmc · bladelogic server automation console13 Ara 2016

  • CVE-1999-0443
    41Planlayın

    Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

    KritikCVSS 10,0İstismar yokEPSS %2

    bmc · patrol agent1 Nis 1999

  • CVE-1999-0801
    41Planlayın

    BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

    KritikCVSS 10,0İstismar yokEPSS %2

    bmc · patrol agent9 Nis 1999

  • CVE-2025-71257
    40Planlayın

    BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication Bypass

    OrtaCVSS 6,9Kavram kanıtıEPSS %45

    bmc · footprints19 Mar 2026

  • CVE-2019-16755
    40Planlayın

    BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perfo

    KritikCVSS 9,8İstismar yokEPSS %3

    bmc · myit digital workplace26 Eyl 2019

  • CVE-2017-17674
    40Planlayın

    BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion.

    KritikCVSS 9,8İstismar yokEPSS %2

    bmc · remedy mid-tier19 May 2021

  • CVE-2022-35865
    40Planlayın

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109.

    KritikCVSS 9,8İstismar yokEPSS %2

    bmc · track-it\!3 Ağu 2022

  • CVE-2022-24047
    40Planlayın

    This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102.

    KritikCVSS 9,8İstismar yokEPSS %2

    bmc · track-it\!18 Şub 2022

  • CVE-2023-34257
    39İzleyin

    An issue was discovered in BMC Patrol through 23.1.00.

    KritikCVSS 9,8İstismar yokEPSS %1

    bmc · patrol agent31 May 2023

  • CVE-2023-26550
    39İzleyin

    A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON fie

    KritikCVSS 9,8İstismar yokEPSS %1

    bmc · control-m25 Şub 2023

  • CVE-2017-9453
    39İzleyin

    BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

    KritikCVSS 9,8İstismar yokEPSS %1

    bmc · server automation5 Eyl 2023

  • CVE-2023-39122
    39İzleyin

    BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.

    KritikCVSS 9,8İstismar yokEPSS %1

    bmc · control-m31 Tem 2023

  • CVE-2024-34399
    39İzleyin

    **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04.

    KritikCVSS 9,8İstismar yokEPSS %1

    bmc · remedy mid-tier18 Eyl 2024

  • CVE-2026-23781
    39İzleyin

    An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22.

    KritikCVSS 9,8İstismar yokEPSS %0

    bmc · control-m\/managed file transfer10 Nis 2026

  • CVE-2025-55109
    38İzleyin

    BMC Control-M/Agent default SSL/TLS configuration authenticated bypass

    KritikCVSS 9,5İstismar yokEPSS %0

    bmc · control-m\/agent16 Eyl 2025

  • CVE-2025-55113
    38İzleyin

    BMC Control-M/Agent unescaped NULL byte in access control list checks

    KritikCVSS 9,5İstismar yokEPSS %0

    bmc · control-m\/agent16 Eyl 2025