Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2494▼ 451 respecto a la semana anterior
Críticas / altas1280▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.5)0.78%—BMC Control-m AgentAI5/11/202517/6/2026
The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration). NOTE:
AplazadaAlta (8.4)0.37%—BMC Control-m AgentAI16/9/202517/6/2026
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases:
AnalizadaMedia (6.3)0.33%—BMC Control-m/agent16/9/202517/6/2026
A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases:
AnalizadaCrítica (9.3)0.16%—BMC Control-m/agent16/9/202517/6/2026
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.
AnalizadaCrítica (9.3)0.17%—BMC Control-m/agent16/9/202517/6/2026
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100…
AplazadaMedia (6.9)0.39%—BMC Control-m AgentAIBMC Control-m ServerAI16/9/202517/6/2026
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-2025-55117 or…
AnalizadaCrítica (9.5)0.29%—BMC Control-m/agent16/9/202517/6/2026
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL…
AnalizadaAlta (7.6)0.22%—BMC Control-m/agent16/9/202517/6/2026
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent…
AnalizadaMedia (5.7)0.13%—BMC Control-m/agent16/9/202517/6/2026
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore…
AplazadaMedia (5.7)0.14%—BMC Control-m/agentsAI16/9/202517/6/2026
Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.
AnalizadaCrítica (9.5)0.35%—BMC Control-m/agent16/9/202517/6/2026
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client…
ModificadaAlta (8.8)1.8%—Bmcsoftware Control-m/agent30/4/202017/6/2026
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
ModificadaAlta (7.5)1.1%—Bmcsoftware Control-m/agent30/4/202017/6/2026
BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.
ModificadaAlta (7.5)1.00%—Bmcsoftware Control-m/agent30/4/202017/6/2026
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
ModificadaAlta (8.8)1.8%—Bmcsoftware Control-m/agent30/4/202017/6/2026
BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
ModificadaAlta (8.8)1.1%—Bmcsoftware Control-m/agent30/4/202017/6/2026
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
ModificadaAlta (8.8)1.6%—Bmcsoftware Control-m/agent30/4/202017/6/2026
A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Control-M/Agent is configured to send the email, allows remote attackers to have unspecified impact via vectors related to the configured IP address or SMTP server.
ModificadaBaja (2.1)0.38%—BMC Software Control-m Agent26/10/200516/6/2026
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.