SQL Injection Vulnerability in BMC Track-It!
CVE-2022-35864
5.3MEDIUM
What is CVE-2022-35864?
A security flaw in BMC Track-It! allows remote attackers to exploit the GetPopupSubQueryDetails endpoint and disclose sensitive information. This issue arises due to insufficient validation of user-supplied input used in SQL query construction. Consequently, attackers with authentication can leverage this vulnerability to access stored credentials, which poses a risk for further compromise of affected systems.
Affected Version(s)
Track-It! 20.21.02.109
