Control M

Vendor:

First CVE: Feb 25, 2023 · Active for 3 years

5
Total CVEs
More Total CVEs than 77% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Control M over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 25, 2023
3 years ago
Most Recent CVE
Mar 18, 2024
858 days ago

CVE Severity & Scoring

Control M5 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None3 (60.0%)
Unknown0 (0.0%)
Required2 (40.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.2
Jul 31, 20239.829NONO
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Feb 25, 20239.824NONO
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users. Leveraging it
Mar 18, 20247.821NONO
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any
Mar 18, 20246.819NONO
Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead
Mar 18, 20245.417NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Control M

Top CWEs

Versions

No cataloged versions.