← Back

Bmc

bmc

79 CVEs • 29 products

Products (29)

Click to collapse
Toggle
Patrol Agent
patrol_agent
Track It!
track-it!
Control M
control-m
Patrol
patrol

CVEs (79)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bmc
1Track It!
May 6, 2026
Dec 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset.
1Bmc
1Track It!
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
1Bmc
1Track It!
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.
1Bmc
1Track It!
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via...Show more
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.Show less
1Bmc
1Patrol Agent
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.
1Bmc
1Service Desk Express
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBac...Show more
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.Show less
1Bmc
1Service Desk Express
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) br...Show more
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.Show less
1Bmc
1Identity Management Suite
Apr 29, 2026
Jun 11, 2012
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that...Show more
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.Show less
1Bmc
6Capacity Management Essentials
Performance Analysis For ServersPerformance Analyzer For Servers+3 more
Apr 29, 2026
Feb 10, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance...Show more
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.Show less
1Bmc
1Patrol Agent
Apr 23, 2026
Jan 27, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled w...Show more
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.Show less
1Bmc
1Patrol Perform Agent
Apr 23, 2026
Apr 22, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.
1Bmc
1Performance Manager
Apr 23, 2026
Apr 22, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modificati...Show more
PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configuredShow less
1Bmc
1Remedy Action Request System
Apr 23, 2026
Jan 18, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine v...Show more
BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.Show less
1Bmc
1Software Control M Agent
Apr 16, 2026
Oct 26, 2005
N/A· v4
N/A· v3
2.1 LOW· v2
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
1Bmc
1Patrol Agent
Apr 16, 2026
Jul 13, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.
1Bmc
1Patrol Agent
Apr 16, 2026
Apr 9, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
1Bmc
1Patrol Agent
Apr 16, 2026
Apr 1, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
BMC Patrol allows any remote attacker to flood its UDP port, causing a denial of service.
1Bmc
1Patrol Agent
Apr 16, 2026
Apr 1, 1999
N/A· v4
N/A· v3
10.0 HIGH· v2
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
1Bmc
1Patrol Agent
Apr 16, 2026
Nov 2, 1998
N/A· v4
N/A· v3
7.2 HIGH· v2
BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.