VYPR

Vendor CVEs

BMC Software

All CVEs

95 total · sorted by risk
  • CVE-2015-5072MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.02

    The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter.

  • CVE-2015-5071MedJan 15, 2020
    risk 0.42cvss 6.5epss 0.02

    AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer servlet.

  • CVE-2019-11216MedDec 4, 2019
    risk 0.42cvss 6.5epss 0.02

    BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attacks to download local files from the server, or do DoS attacks with XML expansion attacks. XXE with direct response and XXE OOB are…

  • CVE-2018-19505MedJan 3, 2019
    risk 0.42cvss 6.5epss 0.02

    Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution…

  • CVE-2017-17678MedMay 19, 2021
    risk 0.40cvss 6.1epss 0.01

    BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.

  • CVE-2018-15528MedAug 21, 2018
    risk 0.40cvss 6.1epss 0.02

    Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared…

  • CVE-2015-9257MedMar 24, 2018
    risk 0.40cvss 6.1epss 0.01

    BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.

  • CVE-2014-9514MedAug 28, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.

  • CVE-2016-5063MedMay 2, 2017
    risk 0.38cvss 5.3epss 0.09

    The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.

  • CVE-2025-55111MedSep 16, 2025
    risk 0.36cvss 5.5epss 0.00

    Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and…

  • CVE-2025-55110MedSep 16, 2025
    risk 0.36cvss 5.5epss 0.00

    Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.

  • CVE-2022-26088MedNov 10, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of…

  • CVE-2017-17675MedMay 19, 2021
    risk 0.35cvss 5.3epss 0.01

    BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

  • CVE-2019-1010147MedJul 26, 2019
    risk 0.35cvss 5.4epss 0.01

    Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector…

  • CVE-2017-18228MedMar 12, 2018
    risk 0.35cvss 5.4epss 0.01

    Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.

  • CVE-2025-55117MedSep 16, 2025
    risk 0.34cvss 5.3epss 0.00

    A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default…

  • CVE-2025-55114MedSep 16, 2025
    risk 0.34cvss 5.3epss 0.00

    The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default…

  • CVE-2024-1606MedMar 18, 2024
    risk 0.30cvss 4.6epss 0.00

    Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to…

  • CVE-2025-71259MedMar 19, 2026
    risk 0.29cvss 4.3epss 0.13

    BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the externalfeed/RSS API component that allows authenticated attackers to trigger arbitrary outbound requests from the server. Attackers can exploit…

  • CVE-2025-71258MedMar 19, 2026
    risk 0.29cvss 4.3epss 0.17

    BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a blind server-side request forgery vulnerability in the searchWeb API component that allows authenticated attackers to cause the server to initiate arbitrary outbound requests. Attackers can exploit improper URL…

  • CVE-2024-34398MedMar 12, 2025
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.

  • CVE-2025-48709LowAug 7, 2025
    risk 0.25cvss 3.8epss 0.00

    BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a…

  • CVE-2014-4872Oct 10, 2014
    risk 0.09cvss —epss 0.79

    BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2)…

  • CVE-2014-8270Dec 12, 2014
    risk 0.05cvss —epss 0.20

    BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset.

  • CVE-2014-4874Oct 10, 2014
    risk 0.04cvss —epss 0.09

    BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.

  • CVE-2014-4873Oct 10, 2014
    risk 0.03cvss —epss 0.04

    SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

  • CVE-2013-4946Jul 29, 2013
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter…

  • CVE-2013-4945Jul 29, 2013
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie…

  • CVE-2012-2959Jun 11, 2012
    risk 0.03cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.

  • CVE-1999-1460Jul 13, 1999
    risk 0.03cvss —epss 0.01

    BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.

  • CVE-2011-0975Feb 10, 2011
    risk 0.01cvss —epss 0.07

    Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00…

  • CVE-2008-5982Jan 27, 2009
    risk 0.01cvss —epss 0.08

    Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.

  • CVE-2026-10540MedJul 1, 2026
    risk 0.00cvss 5.6epss 0.00

    The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions…

  • CVE-2026-10539CriJul 1, 2026
    risk 0.00cvss 9.0epss 0.00

    A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the…

  • CVE-2026-10538HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an…

  • CVE-2014-2591May 14, 2014
    risk 0.00cvss —epss 0.01

    Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.

  • CVE-2007-2136Apr 22, 2007
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.

  • CVE-2007-1972Apr 22, 2007
    risk 0.00cvss —epss 0.04

    PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP…

  • CVE-2007-0310Jan 18, 2007
    risk 0.00cvss —epss 0.02

    BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.

  • CVE-2005-3311Oct 26, 2005
    risk 0.00cvss —epss 0.00

    BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-1999-1355Dec 31, 1999
    risk 0.00cvss —epss 0.01

    BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.

  • CVE-1999-0801Apr 9, 1999
    risk 0.00cvss —epss 0.02

    BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.

  • CVE-1999-0921Apr 1, 1999
    risk 0.00cvss —epss 0.02

    BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.

  • CVE-1999-0443Apr 1, 1999
    risk 0.00cvss —epss 0.02

    Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

  • CVE-1999-1459Nov 2, 1998
    risk 0.00cvss —epss 0.00

    BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.

Page 2 of 2