Vulnerabilities
Vulnerable Software
Bmc:  Security Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in password-manager/changePasswords.do in BMC Identity Management Suite 7.5.00.103 allows remote attackers to hijack the authentication of administrators for requests that change passwords.
CVSS Score
5.1
EPSS Score
0.002
Published
2012-06-11
Stack-based buffer overflow in BMC PATROL Agent Service Daemon for in Performance Analysis for Servers, Performance Assurance for Servers, and Performance Assurance for Virtual Servers 7.4.00 through 7.5.10; Performance Analyzer and Performance Predictor for Servers 7.4.00 through 7.5.10; and Capacity Management Essentials 1.2.00 (7.4.15) allows remote attackers to execute arbitrary code via a crafted length value in a BGS_MULTIPLE_READS command to TCP port 6768.
CVSS Score
10.0
EPSS Score
0.26
Published
2011-02-10
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.
CVSS Score
10.0
EPSS Score
0.14
Published
2009-01-27
PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured
CVSS Score
7.5
EPSS Score
0.036
Published
2007-04-22
Stack-based buffer overflow in bgs_sdservice.exe in BMC Patrol PerformAgent allows remote attackers to execute arbitrary code by connecting to TCP port 10128 and sending certain XDR data, which is not properly parsed.
CVSS Score
7.5
EPSS Score
0.076
Published
2007-04-22
BMC Remedy Action Request System 5.01.02 Patch 1267 generates different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to determine valid account names.
CVSS Score
5.0
EPSS Score
0.009
Published
2007-01-18
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS Score
2.1
EPSS Score
0.001
Published
2005-10-26
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.
CVSS Score
7.2
EPSS Score
0.001
Published
1999-07-13
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
CVSS Score
10.0
EPSS Score
0.01
Published
1999-04-09
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.
CVSS Score
10.0
EPSS Score
0.013
Published
1999-04-01


Contact Us

Shodan ® - All rights reserved