BMC Control-M/Agent
cpe:2.3:a:bmc:control-m/agent:*:*:*:*:*:*:*, +2 more
- <= 9.0.22
A memory corruption vulnerability has been identified in BMC Control-M/Agent versions 9.0.22 and lower, for both UNIX and Windows. This vulnerability can be remotely triggered when SSL/TLS communication is enabled, under specific non-default configuration settings.
Exploitation of this vulnerability leads to memory corruption, which can potentially be exploited to execute arbitrary code or cause a denial-of-service condition.
For Control-M/Agents 9.0.21 and 9.0.22, ensure the 'JAVA_AR' parameter is set to 'Y' and recycle the agent to apply the change. For Control-M/Agents 9.0.20 and lower, upgrade to a supported version and check that 'use_openssl' is set to 'Y'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.