Description
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration). NOTE: The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
9.0.22 (semver)
9.0.21 (semver)
9.0.20 (semver)
9.0.19 (semver)
9.0.18 (semver)
Credits
Airbus SAS - Jean-Romain Garnier - seclab@airbus.com
References
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000442099
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000441962
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000442271