Description
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent and Server.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Product status
9.0.21 (semver)
9.0.20 (semver)
9.0.19 (semver)
9.0.18 (semver)
Credits
Airbus SAS - Jean-Romain Garnier - seclab@airbus.com 
References
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000442099 
bmcapps.my.site.com/.../sc_KnowledgeArticle?sfdcid=000441966