Περιγραφή
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API-s debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.
CVSS 8.8EPSS 0.40099999999999997%Κίνδυνος 0.91
Προβολή πηγής- Δημοσίευση
- 2026-04-10 15:16:23
- Επηρεαζόμενες εκδόσεις
- <9.0.23
- Τύπος
- Installed app
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H