Follow these instructions if you are a BMC Helix customer
Customers should report suspected vulnerabilities through their existing BMC Helix support channels. Using established support processes helps ensure the report is prioritized and investigated within the appropriate customer context.
To expedite handling of the vulnerability, please include:
- Your name, email, and phone number
- BMC Helix product name (For example, TrueSight Server Automation)
- BMC Helix product version (preferably the full version and patch level. For example, v.9.8.01 SP1)
- Detailed description of the vulnerability with steps to reproduce its discovery
- Detailed steps to exploit the vulnerability (if available)
- Applicable CVEs, hostnames, and IP addresses (for vulnerabilities related to infrastructure)