This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Affected Software | Affected Version | How to fix |
---|---|---|
BMC Track-It! |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-22-967 is classified as high due to its potential to disclose sensitive information.
To fix ZDI-22-967, update BMC Track-It! to the latest patched version.
The impact of ZDI-22-967 allows authenticated remote attackers to disclose sensitive information from affected installations.
ZDI-22-967 is a remote information disclosure vulnerability.
BMC Track-It! is the software affected by the ZDI-22-967 vulnerability.