BMC Control-M Unauthenticated SQL Injection Key Details Vulnerability: Unauthenticated SQL Injection Affected Version: BMC Control-M Version < 9.0.20.200 Timeline: - Reported: 26.08.2022 - Fixed Version Released: 12.09.2022 - Patch Released: 21.12.2022 - Disclosure: 05.06.2023 Additional Information Affected Products: BMC Control-M software up to version 9.0.20.200 Vulnerable Parameter: in endpoint Required Headers: and (values can be random) Proof of Concept Database Dump 1. Save request to : 2. Execute SQLMap command: Extracted Database Structure