CVE-2025-55118: BMC Control-M/Agent memory corruption in SSL/TLS communication
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured.
The issue occurs in the following cases:
Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "useopenssl=n"; Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVAAR=N" and "useopenssl=n"
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55118?
CVE-2025-55118 has been classified as a high severity vulnerability due to potential remote exploitation leading to memory corruption.
How do I fix CVE-2025-55118?
To fix CVE-2025-55118, upgrade the Control-M/Agent to a version higher than 9.0.23 or update the SSL/TLS configuration to the default setting.
What versions of Control-M/Agent are affected by CVE-2025-55118?
Control-M/Agent versions 9.0.21 to 9.0.23 are affected by CVE-2025-55118 when configured with non-default SSL/TLS settings.
Can CVE-2025-55118 be exploited remotely?
Yes, CVE-2025-55118 can be exploited remotely, allowing attackers to trigger memory corruptions through SSL/TLS communication.
What is the cause of the vulnerability in CVE-2025-55118?
The vulnerability in CVE-2025-55118 is caused by improper handling of SSL/TLS configurations in Control-M/Agent.