漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
BMC Control-M/MFT 安全漏洞
Vulnerability Description
BMC Control-M/MFT是美国BMC公司的一款企业级文件传输与作业调度集成管理的自动化软件。 BMC Control-M/MFT 9.0.22及之前版本存在安全漏洞,该漏洞源于API管理端点允许未经验证的用户获取API标识符和密钥,可能导致未经授权访问。
CVSS Information
N/A
Vulnerability Type
N/A