BMC Software's vulnerability profile centers on its Control-M job scheduling and automation platform, a narrowly scoped but prominently deployed component of enterprise IT infrastructure. The observed weakness classes recur around OS command injection, buffer overflow, privilege management, and permission assignment, reflecting the privileged execution context and shell-integration demands of workflow automation systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bmcsoftware over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19220HIGH BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2). | Apr 30, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-19217HIGH BMC Control-M/Agent 7.0.00.000 allows OS Command Injection. | Apr 30, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-19215HIGH A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote a | Apr 30, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-19216HIGH BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy. | Apr 30, 2020 | 8.8 | 26 | NO | NO |
CVE-2019-19219HIGH BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download. | Apr 30, 2020 | 7.5 | 24 | NO | NO |
CVE-2019-19218HIGH BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage. | Apr 30, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bmcsoftware.
Media articles that mention a CVE ID that affects a product developed by Bmcsoftware — matched by CVE ID, not by vendor name.