First published: Sat Feb 25 2023(Updated: )
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Control-M | <9.0.20.214 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-26550 is critical with a CVSS score of 9.8.
CVE-2023-26550 affects BMC Control-M versions up to and including 9.0.20.214.
The CWE category for CVE-2023-26550 is CWE-89 (SQL Injection).
An attacker can exploit CVE-2023-26550 by executing arbitrary SQL commands through the memname JSON field.
Yes, upgrading to BMC Control-M version 9.0.20.214 or higher fixes CVE-2023-26550.