Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n".
History

Tue, 16 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
Description Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n".
Title BMC Control-M/Agent memory corruption in SSL/TLS communication
Weaknesses CWE-122
CWE-125
CWE-191
CWE-415
CWE-416
CWE-665
CWE-787
CWE-835
References
Metrics cvssV3_1

{'score': 8.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published: 2025-09-16T12:23:39.683Z

Updated: 2025-09-16T13:18:14.096Z

Reserved: 2025-08-07T07:24:22.470Z

Link: CVE-2025-55118

cve-icon Vulnrichment

Updated: 2025-09-16T13:18:10.446Z

cve-icon NVD

Status : Received

Published: 2025-09-16T13:16:10.060

Modified: 2025-09-16T13:16:10.060

Link: CVE-2025-55118

cve-icon Redhat

No data.