Critical severity9.8NVD Advisory· Published Feb 25, 2023· Updated Jun 17, 2026
CVE-2023-26550
CVE-2023-26550
Description
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <9.0.20.214
Patches
Vulnerability mechanics
References
1- www.synacktiv.com/sites/default/files/2023-02/Synacktiv-ControlM-Multiple-Vulnerabilities.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.