BMC Control-M/Enterprise Manager是BMC公司的一款企业作业调度与资源管理软件。 BMC Control-M/Enterprise Manager存在反序列化注入漏洞,该漏洞源于消息消费功能对用户控制数据的反序列化类型限制不足,可能导致经过身份验证的攻击者通过特制序列化内容触发意外服务器端行为。以下版本受到影响:9.0.20.x版本和更早版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BMC | Control-M/Enterprise Manager | 9.0.21 |
unaffected |
9.0.20< 9.0.21 |
affected | ||
| BMC | Control-M/Server | 9.0.21 |
unaffected |
9.0.20< 9.0.21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BMC | Control-M/Enterprise Manager | 9.0.21 | - |
|
| BMC | Control-M/Server | 9.0.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10539 | 9.0 CRITICAL | Unauthenticated command injection in Control-M/Server communication command |
| CVE-2026-10540 | 5.6 MEDIUM | Weak password hash protection in Control-M/Entreprise Manager |
No comments yet