VendorsBMCcontrol-mall versions
Vulnerabilities

BMC Control-M

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-26550
A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.
Published 2023-02-25 · Modified
9.8EPSS 0.008
CVE-2023-39122
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
Published 2023-07-31 · Modified
9.8EPSS 0.007
CVE-2024-1605
DLL side-loading in BMC Control-M
Published 2024-03-18 · Analyzed
7.8EPSS 0.002
CVE-2024-1604
Incorrect authorization in BMC Control-M
Published 2024-03-18 · Analyzed
6.8EPSS 0.005
CVE-2024-1606
HTML injection in BMC Control-M
Published 2024-03-18 · Analyzed
5.4EPSS 0.004