An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client authentication can bypass the need for a certificate signed by the certificate authority of the organization during authentication on the Control-M/Agent. The Control-M/Agent contains hardcoded certificates which are only trusted as fallback if an empty kdb keystore is used; they are never trusted if a PKCS#12 keystore is used. All of these certificates are now expired. In addition, the Control-M/Agent default kdb and PKCS#12 keystores contain trusted third-party certificates (external recognized CAs and default self-signed demo certificates) which are trusted for client authentication.
The vulnerability results from improper client certificate validation (CWE-295) during authentication to Control-M/Agent. When an empty or default kdb keystore or default PKCS#12 keystore is used, the agent accepts certificates issued by trusted external CAs or default demonstration certificates as valid for client authentication. Additionally, the agent contains hardcoded certificates that are treated as fallback trusted — only in the case of an empty kdb keystore. All hardcoded certificates are already expired, however the mere presence of external and demonstration certificates in default keystores still enables the attack to be carried out.
An attacker can authenticate to Control-M/Agent, bypassing organizational certificate control mechanisms, which may lead to unauthorized access to managed tasks and systems, and consequently to complete takeover of the agent and associated resources.
Patches available from the vendor should be applied according to references (BMC Knowledge Articles sfdcid=000441963 and sfdcid=000442099). As remedial measures, replace default and empty keystores (kdb and PKCS#12) with custom keystores containing only certificates issued by organizational CAs, remove all demonstration certificates and external CA certificates from trusted key stores, and consider migration to versions with active vendor support.
BMC Control-M/Agent versions 9.0.18 through 9.0.20 (out-of-support versions) and potentially earlier unsupported versions when configured with an empty or default kdb keystore or default PKCS#12 keystore.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBmc Control M\/agent
APPBmc≤ 9.0.22
Related vulnerabilities
BMC Control-M/Agent: Bypass ACL przez NULL byte w certyfikacie klienta
Path traversal w BMC Control-M/Agent prowadzący do privilege escalation
Buffer overflow w BMC Control-M/Agent umożliwiający privilege escalation
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that a...
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent version...