Bmc / Control-M
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-48709 | BMC Control-M/Server cleartext database credentials in process lists and logs | MEDIUM | 4.8 | Aug 7, 2025 |
| CVE-2024-1606 | HTML injection in BMC Control-M | MEDIUM | 5.4 | Mar 18, 2024 |
| CVE-2024-1605 | DLL side-loading in BMC Control-M | HIGH | 7.8 | Mar 18, 2024 |
| CVE-2024-1604 | Incorrect authorization in BMC Control-M | MEDIUM | 6.8 | Mar 18, 2024 |
| CVE-2023-39122 | BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by… | CRITICAL | 9.8 | Jul 31, 2023 |
| CVE-2023-26550 | A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field. | CRITICAL | 9.8 | Feb 25, 2023 |
Showing 1 to 6 of 6 CVEs