VYPR

Control-M/Server

by BMC Software

CVEs (3)

  • CVE-2025-48709LowAug 7, 2025
    risk 0.25cvss 3.8epss 0.00

    BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a…

  • CVE-2026-10538Jul 1, 2026
    risk 0.00cvss epss 0.00

    Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an…

  • CVE-2026-10539Jul 1, 2026
    risk 0.00cvss epss 0.00

    A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the…