Show filters
84 Total Results
Displaying 1-10 of 84
Sort by:
Attacker Value
Very High

CVE-2014-2591

Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.
1
Attacker Value
Unknown

CVE-2024-41660

Disclosure Date: July 31, 2024 (last updated August 01, 2024)
slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the slpd-lite daemon on the BMC. Patches will be available in the latest openbmc/slpd-lite repository.
0
Attacker Value
Unknown

CVE-2021-35002

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-14122.
0
Attacker Value
Unknown

CVE-2021-35001

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-14527.
0
Attacker Value
Unknown

CVE-2024-1606

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.
0
Attacker Value
Unknown

CVE-2024-1605

Disclosure Date: March 18, 2024 (last updated October 10, 2024)
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's privileges. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
0
Attacker Value
Unknown

CVE-2024-1604

Disclosure Date: March 18, 2024 (last updated October 10, 2024)
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
0
Attacker Value
Unknown

CVE-2020-35593

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.
Attacker Value
Unknown

CVE-2017-9453

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
Attacker Value
Unknown

CVE-2023-39122

Disclosure Date: July 31, 2023 (last updated October 08, 2023)
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).