If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.
When ACL execution is enabled in Control-M/Agent and the C router is active (default in end-of-support versions 9.0.18–9.0.20, and configurable in newer versions via JAVA_AR setting), verification of the email address in the client certificate terminates prematurely at the first NULL character (byte 0x00). An attacker can craft a certificate in which the email address contains a NULL byte in a strategic location, causing the system to read only the portion of the address before that byte. As a result, a truncated, potentially allowed address is verified, even though the certificate's actual identity is different — leading to ACL rule bypass.
An attacker can bypass configured ACL rules and gain unauthorized access to the Control-M/Agent instance, which may consequently lead to takeover of managed tasks, privilege escalation, and compromise of dependent systems.
Apply patches available from the vendor according to references (BMC Knowledge articles: sfdcid=000441967 and sfdcid=000442099). Additionally, in newer versions, verify the JAVA_AR setting and disable the C router if not essential. Versions under end-of-support (9.0.18–9.0.20) should be updated to a supported version as soon as possible.
BMC Control-M/Agent versions 9.0.18 to 9.0.20 (unsupported versions with C router enabled by default) and potentially earlier unsupported versions; newer versions are vulnerable if the C router was manually enabled via JAVA_AR setting
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XBmc Control M\/agent
APPBmc≤ 9.0.22
Related vulnerabilities
BMC Control-M/Agent: Authentication Bypass przez niezabezpieczony keystore
Path traversal w BMC Control-M/Agent prowadzący do privilege escalation
Buffer overflow w BMC Control-M/Agent umożliwiający privilege escalation
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that a...
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent version...