BMC
BMC Track-it!: vulnerabilidades y CVE
BMC Track-it! tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-35002 | Alta (8.8) | 1.7% | — | 7 may 2024 | BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to… |
| CVE-2021-35001 | Media (6.5) | 0.76% | — | 7 may 2024 | BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication… |
| CVE-2022-35865 | Crítica (9.8) | 1.9% | — | 3 ago 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within… |
| CVE-2022-35864 | Media (6.5) | 1.6% | — | 3 ago 2022 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists… |
| CVE-2022-24047 | Crítica (9.8) | 1.9% | — | 18 feb 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within… |
| CVE-2016-6599 | Crítica (9.8) | 12% | — | 30 ene 2018 | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file… |
| CVE-2016-6598 | Crítica (9.8) | 19% | — | 30 ene 2018 | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the… |
| CVE-2014-8270 | Media (5) | 20% | — | 12 dic 2014 | BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset. |
| CVE-2014-4874 | Media (4) | 8.9% | — | 10 oct 2014 | BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page. |
| CVE-2014-4873 | Media (6.5) | 4.2% | — | 10 oct 2014 | SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data. |
| CVE-2014-4872 | Alta (7.5) | 79% | — | 10 oct 2014 | BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information… |