Vulnerability Description
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetPopupSubQueryDetails endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-16690.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bmc | Track-It\! | 20.19.03 |
Related Weaknesses (CWE)
References
- https://community.bmc.com/s/article/Security-vulnerabilities-patched-in-Track-ItPatchVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-967/Third Party AdvisoryVDB Entry
- https://community.bmc.com/s/article/Security-vulnerabilities-patched-in-Track-ItPatchVendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-967/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2022-35864?
CVE-2022-35864 is a vulnerability with a CVSS score of 6.5 (MEDIUM). This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vulnerability. The spec...
How severe is CVE-2022-35864?
CVE-2022-35864 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35864?
Check the references section above for vendor advisories and patch information. Affected products include: Bmc Track-It\!.