CVEs we hold for Bmc
Records whose assigning authority named Bmc as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-10540Weak password hash protection in Control-M/Entreprise ManagerBMC Control-M/Enterprise Manager
CVE-2026-10539Unauthenticated command injection in Control-M/Server communication commandBMC Control-M/Server
CVE-2025-71260BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 VIEWSTATE Deserialization RCEBMC Software, Inc. FootPrints
CVE-2025-71259BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in externalfeed/RSSBMC Software, Inc. FootPrints
CVE-2025-71258BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Blind SSRF in searchWebBMC Software, Inc. FootPrints
CVE-2025-71257BMC FootPrints ITSM 20.20.02 <= 20.24.01.001 Authentication BypassBMC Software, Inc. FootPrints
CVE-2025-55113BMC Control-M/Agent unescaped NULL byte in access control list checksBMC Control-M/Agent
CVE-2025-55109BMC Control-M/Agent default SSL/TLS configuration authenticated bypassBMC Control-M/Agent
CVE-2025-55108BMC Control-M/Agent default configuration does not enforce SSL/TLS allowing unauthorized actions and remote code…BMC Control-M/Agent
CVE-2025-48709BMC Control-M/Server cleartext database credentials in process lists and logsBMC Control-M/Server
CVE-2024-58298Compuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File UploadBMC Software Compuware iStrobe Web
CVE-2021-35002BMC Track-It! Unrestricted File Upload Remote Code Execution VulnerabilityBMC Track-It!
CVE-2021-35001BMC Track-It! GetData Missing Authorization Information Disclosure VulnerabilityBMC Track-It!
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.