CVE-2023-26550: SQL Injection
Published Feb 25, 2023
·Updated
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Affected Software
1 affected component
BMC Control-M<9.0.20.214
Event History
Feb 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26550?
The severity of CVE-2023-26550 is critical with a CVSS score of 9.8.
2
How does CVE-2023-26550 affect BMC Control-M?
CVE-2023-26550 affects BMC Control-M versions up to and including 9.0.20.214.
3
What is the CWE category for CVE-2023-26550?
The CWE category for CVE-2023-26550 is CWE-89 (SQL Injection).
4
How can an attacker exploit CVE-2023-26550?
An attacker can exploit CVE-2023-26550 by executing arbitrary SQL commands through the memname JSON field.
5
Is there a fix available for CVE-2023-26550?
Yes, upgrading to BMC Control-M version 9.0.20.214 or higher fixes CVE-2023-26550.