logo

Bypassing access control in BMC Control-D Report Viewer

ID: 9176c249-f6a1-52d3-b46c-c8641c995969

STIX ID: report--9176c249-f6a1-52d3-b46c-c8641c995969

Feed Name: SensePost Blog

Threat Score
55/100

Date Published: 2019-12-03

Date Updated: 2026-04-29

...
...

This report documents an authentication-bypass vulnerability in BMC Control‑D WebAccess: the web CGI communicates with a local service on TCP port 7777 using a protocol that trusts the provided username, enabling an attacker who can connect to that port to request reports as arbitrary users. The flaw affects versions up to 9.0.18 and was remediated in release 9.0.19 with patches for supported platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.