BMC Response To ZDI: It’s Magically Litigious!
Dave G. | April 20th, 2007 | Filed Under: Disclosure, Industry Punditry
Earlier this week, ZDI released a slew of vulnerabilities across a number of enterprise software vendors. And if you look at how most of the vendors responded to ZDI, you would see something like:
XXX has released an update that addresses the vulnerability. It is available at:http://update/pathtoupdate
Short, sweet and to the point… However, one vendor had a fascinating response:
BMC has provided the following statement: “[This issue] has been addressed, and a patch has been made available to our customers. A flash bulletin has been created describing the patch and will be sent to all affected customers in the next few days.BMC has a formal customer support mechanism in place to provide solutions to security issues brought to us by those who have legally licensed our software. In cases where security issues are brought to my attention by individuals/vendors who do not have legal access to our products, we will investigate their merit; however the issues will be addressed at our own discretion and according to our understanding of their severity.
Finally, please note that in the future, I will only communicate resolutions and workarounds to licensed customers who are using our software legally. For a more meaningful dialogue around these issues and to be notified of any available patches, I urge all licensed customers to use BMC’s support mechanism.”


Add New Comment
Viewing 5 Comments
Thanks. Your comment is awaiting approval by a moderator.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Do you already have an account? Log in and claim this comment.
Add New Comment
Trackbacks