← Back

Bmc

bmc

79 CVEs • 29 products

Products (29)

Click to collapse
Toggle
Patrol Agent
patrol_agent
Track It!
track-it!
Control M
control-m
Patrol
patrol

CVEs (79)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bmc
1Patrol Agent
Jun 17, 2026
Oct 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially craf...Show more
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution.Show less
1Bmc
1Myit Digital Workplace
Jun 17, 2026
Sep 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running t...Show more
BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remote attackers to perform pre-authenticated remote commands execution on the Operating System running the targeted application. Affected DWP versions: versions: 3.x to 18.x, all versions, service packs, and patches are affected by this vulnerability. Affected SmartIT versions: 1.x, 2.0, 18.05, 18.08, and 19.02, all versions, service packs, and patches are affected by this vulnerability.Show less
2Bmc
Yellowfinbi
2Remedy Smart Reporting
Yellowfin Bi
Jun 17, 2026
Jul 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browse...Show more
Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. The impact is: Victim attacked and access admin functionality through their browser and control browser. The component is: MIAdminStyles.i4. The attack vector is: Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. The fixed version is: 7.4 and later.Show less
1Bmc
1Patrol Agent
Jun 17, 2026
May 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this networ...Show more
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.Show less
1Bmc
2Remedy Action Request System
Remedy Mid Tier
Nov 21, 2024
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admi...Show more
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.Show less
1Bmc
1Patrol Agent
Nov 21, 2024
Jan 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was fo...Show more
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided for the given username is correct; it does not verify the permissions of the user on the network. This means if you have PATROL Agent installed on a high value target (domain controller), you can use a low privileged domain user to authenticate with PatrolCli and then connect to the domain controller and run commands as SYSTEM. This means any user on a domain can escalate to domain admin through PATROL Agent. NOTE: the vendor disputes this because they believe it is adequate to prevent this escalation by means of a custom, non-default configurationShow less
1Bmc
1Remedy Action Request System Server
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:W...Show more
Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.Show less
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 24, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 12, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
1Bmc
1Remedy Action Request System
Nov 21, 2024
Mar 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
1Bmc
1Track It!
Nov 21, 2024
Jan 30, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that...Show more
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database name, username and password as well as the domain administrator username and password. These are encrypted with a fixed key and IV ("NumaraIT") using the DES algorithm. The domain administrator username and password can only be obtained if the Self-Service component is enabled, which is the most common scenario in enterprise deployments.Show less
1Bmc
1Track It!
Nov 21, 2024
Jan 30, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the...Show more
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.Show less
1Bmc
1Footprints Service Core
May 13, 2026
Aug 28, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
1Bmc
1Patrol
May 13, 2026
Aug 23, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid root and the RPATH variable begins with the .: substring.
1Bmc
1Server Automation
May 13, 2026
May 2, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.
1Bmc
1Remedy Action Request System
May 6, 2026
Dec 21, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.
1Bmc
1Bladelogic Server Automation Console
May 6, 2026
Dec 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in t...Show more
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.Show less
1Bmc
1Patrol
May 6, 2026
Dec 2, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" pr...Show more
In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their privileges to root.Show less
1Bmc
1Bladelogic Server Automation Console
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sendin...Show more
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.Show less
1Bmc
1Bladelogic Server Automation Console
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet...Show more
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.Show less