CVE-2023-39122: SQL Injection
Published Jul 31, 2023
·Updated
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
Affected Software
1 affected component
BMC Control-M<9.0.21
Event History
Jul 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39122?
CVE-2023-39122 is a vulnerability in BMC Control-M that allows SQL injection via the /RF-Server/report/deleteReport report-id parameter.
2
How severe is CVE-2023-39122?
CVE-2023-39122 has a severity rating of 9.8 (critical).
3
What software versions are affected by CVE-2023-39122?
BMC Control-M versions up to 9.0.20.200 are affected by CVE-2023-39122.
4
How can I fix CVE-2023-39122?
CVE-2023-39122 can be fixed by upgrading to BMC Control-M version 9.0.21 or applying a patch for version 9.0.20.200.
5
Is there any reference for CVE-2023-39122?
Yes, you can find more information about CVE-2023-39122 at the following link: [reference](https://github.com/DojoSecurity/BMC-Control-M-Unauthenticated-SQL-Injection).