CRITICAL🇵🇱 Wersja polska

CVE-2025-55113

CVSS 9.5v4.0pub. 2025-09-16upd. 2025-10-10

If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.

🤖 AI Analysis
How it works

When ACL execution is enabled in Control-M/Agent and the C router is active (default in end-of-support versions 9.0.18–9.0.20, and configurable in newer versions via JAVA_AR setting), verification of the email address in the client certificate terminates prematurely at the first NULL character (byte 0x00). An attacker can craft a certificate in which the email address contains a NULL byte in a strategic location, causing the system to read only the portion of the address before that byte. As a result, a truncated, potentially allowed address is verified, even though the certificate's actual identity is different — leading to ACL rule bypass.

Impact

An attacker can bypass configured ACL rules and gain unauthorized access to the Control-M/Agent instance, which may consequently lead to takeover of managed tasks, privilege escalation, and compromise of dependent systems.

Mitigation & patch

Apply patches available from the vendor according to references (BMC Knowledge articles: sfdcid=000441967 and sfdcid=000442099). Additionally, in newer versions, verify the JAVA_AR setting and disable the C router if not essential. Versions under end-of-support (9.0.18–9.0.20) should be updated to a supported version as soon as possible.

Who is affected

BMC Control-M/Agent versions 9.0.18 to 9.0.20 (unsupported versions with C router enabled by default) and potentially earlier unsupported versions; newer versions are vulnerable if the C router was manually enabled via JAVA_AR setting

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Bmc Control M\/agent

    APP
    Bmc
    ≤ 9.0.22
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-55109CRITICAL9.5PL ✓same product

BMC Control-M/Agent: Authentication Bypass przez niezabezpieczony keystore

CVE-2025-55115CRITICAL9.3PL ✓same product

Path traversal w BMC Control-M/Agent prowadzący do privilege escalation

CVE-2025-55116CRITICAL9.3PL ✓same product

Buffer overflow w BMC Control-M/Agent umożliwiający privilege escalation

CVE-2025-55112HIGH7.6same product

Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that a...

CVE-2025-55111MEDIUM5.7same product

Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent version...