CVE-2014-4873: Bmc Track-It!

Medium severity, CVSS 6.5. EPSS: 4.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

Affected products

  • Bmc Track-It!: version 11.3.0.355 only

Published 2014-10-10. Last modified 2026-06-17.