SQL Injection Vulnerability in BMC Control-M Software
CVE-2023-26550
9.8CRITICAL
What is CVE-2023-26550?
A SQL injection vulnerability exists in BMC Control-M versions prior to 9.0.20.214. This flaw allows attackers to exploit the memname JSON field, enabling the execution of arbitrary SQL commands. Successful exploitation can lead to unauthorized access to sensitive data and potential manipulation of the database.
