Bypassing access control in BMC Control-D Report Viewer
ID: 9176c249-f6a1-52d3-b46c-c8641c995969
STIX ID: report--9176c249-f6a1-52d3-b46c-c8641c995969
Feed Name: SensePost Blog
Threat Score
This report documents an authentication-bypass vulnerability in BMC Control‑D WebAccess: the web CGI communicates with a local service on TCP port 7777 using a protocol that trusts the provided username, enabling an attacker who can connect to that port to request reports as arbitrary users. The flaw affects versions up to 9.0.18 and was remediated in release 9.0.19 with patches for supported platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
