← Vulnerability feed

Vulnerability record · CVE-2021-35001 · published 7 May 2024

CVE-2021-35001: Bmc track-it\! missing authorization vulnerability

Bmc · Track It\!

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-14527.

6.5 CVSS 3.1 Medium EPSS 0.76% · top 46.7% CWE-862 · Missing authorization
6.5CVSS 3.1 base score
0.76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the GetData endpoint. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-14527.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35001 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35865Bmc track-it\! missing authentication for critical function vulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not re…EPSS 1.9%9.8CVE-2022-24047Bmc track-it\! authentication bypass via alternate path vulnerabilityThis vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not re…EPSS 1.9%9.8CVE-2016-6598Bmc track-it\! improper access control vulnerabilityBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service cont…EPSS 19%9.8CVE-2016-6599Bmc track-it\! vulnerabilityBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service c…EPSS 12%8.8CVE-2021-35002Bmc track-it\! unrestricted file upload vulnerabilityBMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on a…EPSS 1.7%7.5CVE-2014-4872BMC Track-It! unauthenticated .NET Remoting service allows file upload and code executionBMC Track-It! 11.3.0.355 exposes TCP port 9010 without requiring authentication, and its FileStorageService and ConfigurationService accept .NET Remo…EPSS 79%analysed6.5CVE-2022-35864Bmc track-it\! sql injection vulnerabilityThis vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication …EPSS 1.6%6.5CVE-2014-4873Bmc track-it\! sql injection vulnerabilitySQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL command…EPSS 4.2%

Source: NIST National Vulnerability Database (record CVE-2021-35001), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.