Authentication Bypass Vulnerability in BMC Track-It! by BMC Software
CVE-2022-24047

5.3MEDIUM

Key Information:

Vendor

Bmc

Status
Vendor
CVE Published:
18 February 2022

What is CVE-2022-24047?

This vulnerability allows remote attackers to bypass authentication mechanisms in BMC Track-It! 20.21.01.102. The flaw resides in the HTTP request authorization process, where insufficient authentication enables unauthorized access to system functionalities. This exposure may allow attackers to exploit the system without any authentication required, posing significant security risks. For detailed advisories and patch information, refer to the resources provided by the Zero Day Initiative and BMC community.

Affected Version(s)

Track-It! 20.21.01.102

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Markus Wulftange (@mwulftange)
.