First published: Mon Jul 31 2023(Updated: )
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Control-M | <9.0.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39122 is a vulnerability in BMC Control-M that allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.
CVE-2023-39122 has a severity rating of 9.8 (critical).
BMC Control-M versions up to 9.0.20.200 are affected by CVE-2023-39122.
CVE-2023-39122 can be fixed by upgrading to BMC Control-M version 9.0.21 or applying a patch for version 9.0.20.200.
Yes, you can find more information about CVE-2023-39122 at the following link: [reference](https://github.com/DojoSecurity/BMC-Control-M-Unauthenticated-SQL-Injection).