← Vulnerability feed

Vulnerability record · CVE-2014-4873 · published 10 October 2014

CVE-2014-4873: Bmc track-it\! sql injection vulnerability

Bmc · Track It\!

SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

6.5 CVSS 2.0 Medium EPSS 4.2% · top 9.4% CWE-89 · SQL injection
6.5CVSS 2.0 base score
4.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-4873 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35865Bmc track-it\! missing authentication for critical function vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…EPSS 1.9%9.8CVE-2022-24047Bmc track-it\! authentication bypass via alternate path vulnerabilityThis vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…EPSS 1.9%9.8CVE-2016-6598Bmc track-it\! improper access control vulnerabilityBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont…EPSS 19%9.8CVE-2016-6599Bmc track-it\! vulnerabilityBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service c…EPSS 12%8.8CVE-2021-35002Bmc track-it\! unrestricted file upload vulnerabilityBMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…EPSS 1.7%7.5CVE-2014-4872BMC Track-It! unauthenticated .NET Remoting service allows file upload and code executionBMC Track-It! 11.3.0.355 exposes TCP port 9010 without requiring authentication, and its FileStorageService and ConfigurationService accept .NET Remo…EPSS 79%analysed6.5CVE-2021-35001Bmc track-it\! missing authorization vulnerabilityBMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…EPSS 0.76%6.5CVE-2022-35864Bmc track-it\! sql injection vulnerabilityThis vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication …EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2014-4873), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.