CVE-2025-55113: BMC Control-M/Agent unescaped NULL byte in access control list checks
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVAAR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55113?
CVE-2025-55113 is rated as a medium severity vulnerability affecting specific versions of BMC Control-M/Agent.
How do I fix CVE-2025-55113?
To fix CVE-2025-55113, apply the latest security patches or upgrade to a supported version of BMC Control-M/Agent.
Which versions of BMC Control-M/Agent are affected by CVE-2025-55113?
BMC Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions are affected by CVE-2025-55113.
What kind of vulnerability is CVE-2025-55113?
CVE-2025-55113 is a vulnerability associated with Access Control List enforcement in certain configurations of BMC Control-M/Agent.
Is CVE-2025-55113 still exploitable in newer versions of BMC Control-M/Agent?
CVE-2025-55113 may not be exploitable in newer versions of BMC Control-M/Agent if proper security measures and configurations are applied.