CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bmc 1Control M/managed File Transfer Jun 17, 2026 Apr 10, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obt...Show more |
1Bmc 1Control M/managed File Transfer Jun 17, 2026 Apr 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets,...Show more |
1Bmc 1Control M/managed File Transfer Jun 17, 2026 Apr 10, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input valida...Show more |