Vulnerabilities in BMC

23 results
Vexday analysis

A BMC apresenta 23 vulnerabilidades documentadas, com 6 classificadas como críticas, mas nenhuma sob exploração ativa conhecida no momento. A fraqueza predominante é CWE-121 (stack-based buffer overflow), indicando deficiências estruturais no tratamento de memória; o risco recente é moderado, com apenas 3 CVEs publicadas nos últimos 90 dias.

CVE-2022-24047MEDIUMThis vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication EPSS 1.9%CVE-2022-35865HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication EPSS 1.8%CVE-2021-35002HIGHBMC Track-It! Unrestricted File Upload Remote Code Execution VulnerabilityEPSS 1.7%CVE-2022-35864MEDIUMThis vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. AuthenEPSS 1.5%CVE-2025-55108CRITICALBMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code executionEPSS 0.8%CVE-2021-35001LOWBMC Track-It! GetData Missing Authorization Information Disclosure VulnerabilityEPSS 0.8%CVE-2024-1604MEDIUMIncorrect authorization in BMC Control-MEPSS 0.5%CVE-2024-1606MEDIUMHTML injection in BMC Control-MEPSS 0.4%CVE-2025-55114MEDIUMBMC Control-M/Agent improper IP address filtering orderEPSS 0.4%CVE-2025-55118HIGHBMC Control-M/Agent memory corruption in SSL/TLS communicationEPSS 0.3%CVE-2025-55109CRITICALBMC Control-M/Agent default SSL/TLS configuration authenticated bypassEPSS 0.3%CVE-2025-55117MEDIUMBMC Control-M/Agent buffer overflow in SSL/TLS communicationEPSS 0.3%CVE-2025-55113CRITICALBMC Control-M/Agent unescaped NULL byte in access control list checksEPSS 0.3%CVE-2026-10539CRITICALUnauthenticated command injection in Control-M/Server communication commandEPSS 0.3%CVE-2026-10538HIGHImproper deserialization handling in Control-M ComponentsEPSS 0.2%CVE-2024-1605MEDIUMDLL side-loading in BMC Control-MEPSS 0.2%CVE-2025-55112HIGHBMC Control-M/Agent hardcoded Blowfish keysEPSS 0.2%CVE-2025-55115CRITICALBMC Control-M/Agent path traversal local privilege escalationEPSS 0.2%CVE-2025-55116CRITICALBMC Control-M/Agent buffer overflow local privilege escalationEPSS 0.1%CVE-2025-55110MEDIUMBMC Control-M/Agent hardcoded default keystore passwordEPSS 0.1%