Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
BMC Control-M/Agent memory corruption in SSL/TLS communication
Vulnerability Description
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
Vulnerability Type
堆缓冲区溢出
Vulnerability Title
BMC Control-M 安全漏洞
Vulnerability Description
BMC Control-M是BMC公司的一个应用程序。简化了本地或作为服务的应用程序和数据工作流编排。 BMC Control-M 9.0.20版本、9.0.21版本和9.0.22版本存在安全漏洞,该漏洞源于SSL/TLS通信配置不当,可能导致远程触发内存损坏。
CVSS Information
N/A
Vulnerability Type
N/A