VYPR

Control M

by BMC Software

CVEs (6)

  • CVE-2023-39122CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).

  • CVE-2023-26550CriFeb 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.

  • CVE-2026-23780HigApr 10, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful…

  • CVE-2024-1605MedMar 18, 2024
    risk 0.43cvss 6.6epss 0.00

    BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it leads to loading of a potentially malicious libraries, which will execute with the application's…

  • CVE-2024-1604MedMar 18, 2024
    risk 0.42cvss 6.4epss 0.00

    Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know…

  • CVE-2024-1606MedMar 18, 2024
    risk 0.30cvss 4.6epss 0.00

    Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to…