BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
References
Link | Resource |
---|---|
https://github.com/DojoSecurity/BMC-Control-M-Unauthenticated-SQL-Injection | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-31 23:15
Updated : 2023-08-04 16:51
NVD link : CVE-2023-39122
Mitre link : CVE-2023-39122
CVE.ORG link : CVE-2023-39122
JSON object : View
Products Affected
bmc
- control-m
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')