CVE-2025-55115: BMC Control-M/Agent path traversal local privilege escalation
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100 and above.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55115?
CVE-2025-55115 is classified as a high-severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2025-55115?
To remediate CVE-2025-55115, upgrade to a supported version of the BMC Control-M/Agent that is beyond 9.0.20.
Who is affected by CVE-2025-55115?
CVE-2025-55115 affects users running the out-of-support BMC Control-M/Agent versions 9.0.18 to 9.0.20 and possibly earlier versions.
What can an attacker do with CVE-2025-55115?
An attacker with access to the system running the BMC Control-M/Agent can exploit CVE-2025-55115 to escalate their privileges.
Is my version of BMC Control-M/Agent vulnerable to CVE-2025-55115?
If you are using BMC Control-M/Agent version 9.0.18 to 9.0.20 or earlier unsupported versions, then your installation is vulnerable to CVE-2025-55115.