VYPR

Control M\/agent

by BMC Software

CVEs (7)

  • CVE-2025-55113CriSep 16, 2025
    risk 0.59cvss 9.0epss 0.00

    If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions),…

  • CVE-2025-55109CriSep 16, 2025
    risk 0.59cvss 9.0epss 0.00

    An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed…

  • CVE-2025-55116HigSep 16, 2025
    risk 0.57cvss 8.8epss 0.00

    A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.

  • CVE-2025-55115HigSep 16, 2025
    risk 0.57cvss 8.8epss 0.00

    A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.…

  • CVE-2025-55112HigSep 16, 2025
    risk 0.48cvss 7.4epss 0.00

    Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt…

  • CVE-2025-55111MedSep 16, 2025
    risk 0.36cvss 5.5epss 0.00

    Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and…

  • CVE-2025-55117MedSep 16, 2025
    risk 0.34cvss 5.3epss 0.00

    A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default…