漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
BMC Control-M/Agent insecure default file permissions
Vulnerability Description
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore and policies. An attacker with local access to the system running the Agent can access these files.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
缺省权限不正确
Vulnerability Title
BMC Control-M 安全漏洞
Vulnerability Description
BMC Control-M是BMC公司的一个应用程序。简化了本地或作为服务的应用程序和数据工作流编排。 BMC Control-M 9.0.18版本至9.0.20版本及之前不受支持的版本存在安全漏洞,该漏洞源于文件权限设置过于宽松,可能导致本地攻击者访问包含密钥和密码的文件。
CVSS Information
N/A
Vulnerability Type
N/A