CVE-2025-55117: BMC Control-M/Agent buffer overflow in SSL/TLS communication
A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured.
The issue occurs in the following cases:
Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "useopenssl=n"; Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVAAR=N" and "useopenssl=n".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55117?
CVE-2025-55117 has a high severity rating due to the potential for remote exploitation through a stack-based buffer overflow.
How do I fix CVE-2025-55117?
To fix CVE-2025-55117, update BMC Control-M/Agent to a version beyond 9.0.22 where the vulnerability has been addressed.
What versions of BMC Control-M/Agent are affected by CVE-2025-55117?
Versions 9.0.20 and 9.0.21 of BMC Control-M/Agent are affected by CVE-2025-55117.
What causes the vulnerability in CVE-2025-55117?
CVE-2025-55117 is caused by a stack-based buffer overflow during the formatting of error messages when SSL/TLS communication is configured.
Is remote exploitation possible with CVE-2025-55117?
Yes, CVE-2025-55117 can be remotely exploited, allowing attackers to trigger the buffer overflow.