CVE-2014-4872
CVE-2014-4872 is a high-severity vulnerability in Bmc Track-it! with a CVSS 2.0 base score of 7.5. Its EPSS exploit-prediction score of 79% places it in the 100th percentile, indicating an elevated likelihood of exploitation. The underlying weakness is classified as CWE-306.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 79% (100th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-306
- Affected product: Bmc Track-it!
- Published:
- Last modified:
Description
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.
Frequently asked questions
- What is CVE-2014-4872?
- BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.
- How severe is CVE-2014-4872?
- CVE-2014-4872 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2014-4872 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 79% (100th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2014-4872?
- CVE-2014-4872 affects Bmc Track-it!. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2014-4872?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2014-4872 published?
- CVE-2014-4872 was published on 2014-10-10 and last updated on 2026-06-17.
References
- http://packetstormsecurity.com/files/128594/BMC-Track-it-Remote-Code-Execution-SQL-Injection.html
- http://www.kb.cert.org/vuls/id/121036
- https://raw.githubusercontent.com/pedrib/PoC/master/generic/bmc-track-it-11.3.txt
Affected products (1)
- cpe:2.3:a:bmc:track-it\!:11.3.0.355:*:*:*:*:*:*:*
More vulnerabilities in Bmc Track-it!
- CVE-2022-35865 — Critical (CVSS 9.8): This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!…
- CVE-2022-24047 — Critical (CVSS 9.8): This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It!…
- CVE-2016-6599 — Critical (CVSS 9.8): BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service…
- CVE-2016-6598 — Critical (CVSS 9.8): BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService)…
- CVE-2021-35002 — High (CVSS 8.8): BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers…
- CVE-2021-35001 — Medium (CVSS 6.5): BMC Track-It! GetData Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote…
All CVEs affecting Bmc Track-it! →
Other CWE-306 (Missing Authentication for Critical Function) vulnerabilities
- CVE-2026-85889 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges…
- CVE-2026-92808 — Critical (CVSS 10.0): A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An…
- CVE-2026-59971 — Critical (CVSS 10.0): MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to…
- CVE-2026-80462 — Critical (CVSS 10.0): A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to…
- CVE-2026-75754 — Critical (CVSS 10.0): Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in…
- CVE-2026-70352 — Critical (CVSS 10.0): Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges…
Browse all CWE-306 (Missing Authentication for Critical Function) vulnerabilities →