Medium severity4.6NVD Advisory· Published Mar 18, 2024· Updated Jun 17, 2026
CVE-2024-1606
CVE-2024-1606
Description
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker.
Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
39.0.20, 9.0.21+ 1 more
- (no CPE)range: 9.0.20, 9.0.21
- (no CPE)range: 9.0.20
Patches
Vulnerability mechanics
References
3- cert.pl/en/posts/2024/03/CVE-2024-1604nvdThird Party Advisory
- cert.pl/posts/2024/03/CVE-2024-1604nvdThird Party Advisory
- www.bmc.com/it-solutions/control-m.htmlnvdProduct
News mentions
0No linked articles in our index yet.