BMC control-m/server是BMC公司的一个工作负载自动化调度平台。 BMC Control-M/Server 9.0.20.x版本至9.0.21.200版本存在授权问题漏洞,该漏洞源于未充分过滤或清理用户提供的输入,可能导致未经身份验证的攻击者在特定条件下执行未经授权的命令,进而破解服务器。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| BMC | Control-M/Server | 9.0.21.300 |
unaffected |
9.0.20≤ 9.0.21.200 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BMC | Control-M/Server | 9.0.21.300 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10538 | 8.0 HIGH | Improper deserialization handling in Control-M Components |
| CVE-2026-10540 | 5.6 MEDIUM | Weak password hash protection in Control-M/Entreprise Manager |
No comments yet