Track It

Vendor:

First CVE: Oct 10, 2014 · Active for 11 years

11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 61% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Track It over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2014
11 years ago
Most Recent CVE
May 7, 2024
808 days ago

CVE Severity & Scoring

Track It11 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (63.6%)
Unknown4 (36.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High0 (0.0%)
Unknown4 (36.4%)
User Interaction
None7 (63.6%)
Unknown4 (36.4%)
Required0 (0.0%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None4 (36.4%)
Unknown4 (36.4%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive cred
Oct 10, 20147.583NOYES
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploa
Jan 30, 20189.851NOYES
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be us
Jan 30, 20189.849NOYES
This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerab
Aug 3, 20229.831NONO
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a
Dec 12, 20145.031NOYES
SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.
Oct 10, 20146.531NOYES
This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerab
Feb 18, 20229.829NONO
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.
Oct 10, 20144.029NOYES
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Tr
May 7, 20248.824NONO
This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! 20.21.02.109. Authentication is required to exploit this vul
Aug 3, 20226.522NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
18.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
45.5% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Track It

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20.21.0228.21.4%00
20.21.01.10219.81.9%00
20.21.0147.91.3%00
20.20.0347.91.3%00
20.20.0247.91.3%00
20.20.0147.91.3%00
20.19.0347.91.3%00
20.19.0227.71.2%00
20.19.0127.71.2%00
11.429.815.8%02
11.3.0.35536.030.2%03
11.315.020.1%01