Bmc

Control-m/server

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 01.07.2026 08:16:20
  • Zuletzt bearbeitet 01.07.2026 19:59:44

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. ...

  • EPSS 0.27%
  • Veröffentlicht 01.07.2026 08:16:20
  • Zuletzt bearbeitet 01.07.2026 19:59:44

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially lea...

  • EPSS 0.12%
  • Veröffentlicht 07.08.2025 20:15:28
  • Zuletzt bearbeitet 18.12.2025 17:34:09

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/...