CVE-2007-1972

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/04/2007
Last modified:
09/04/2025

Description

PatrolAgent.exe in BMC Performance Manager does not require authentication for requests to modify configuration files, which allows remote attackers to execute arbitrary code via a request on TCP port 3181 for modification of the masterAgentName and masterAgentStartLine SNMP parameters. NOTE: the vendor disputes this vulnerability, stating that it does not exist when the system is properly configured

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bmc:performance_manager:*:*:*:*:*:*:*:*