PT-2025-37945 · Bmc · Control-M/Agent

CVE-2025-55115

·

Published

2025-09-16

·

Updated

2025-09-16

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Control-M/Agent versions 9.0.18 through 9.0.20
Description A path traversal in Control-M/Agent can lead to local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts out-of-support versions and potentially earlier unsupported versions.
Recommendations Update to version 9.0.20.100 or later.

Fix

LPE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55115

Affected Products

Control-M/Agent