CVE-2024-1604
Incorrect authorization in BMC Control-M
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
La autorización inadecuada en el módulo de creación y gestión de informes de las ramas 9.0.20 y 9.0.21 de BMC Control-M permite a los usuarios registrados leer y realizar cambios no autorizados en cualquier informe disponible dentro de la aplicación, incluso sin los permisos adecuados. El atacante debe conocer el identificador único del informe que quiere manipular. La solución para la rama 9.0.20 se lanzó en la versión 9.0.20.238. La solución para la rama 9.0.21 se lanzó en la versión 9.0.21.201.
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-18 CVE Reserved
- 2024-03-18 CVE Published
- 2024-03-19 EPSS Updated
- 2024-10-10 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
- CWE-863: Incorrect Authorization
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://cert.pl/en/posts/2024/03/CVE-2024-1604 | Third Party Advisory | |
https://cert.pl/posts/2024/03/CVE-2024-1604 | Third Party Advisory | |
https://www.bmc.com/it-solutions/control-m.html | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
BMC Search vendor "BMC" | Control-M Search vendor "BMC" for product "Control-M" | >= 9.0.20.0 < 9.0.20.238 Search vendor "BMC" for product "Control-M" and version " >= 9.0.20.0 < 9.0.20.238" | en |
Affected
| ||||||
BMC Search vendor "BMC" | Control-M Search vendor "BMC" for product "Control-M" | >= 9.0.21.0 < 9.0.21.201 Search vendor "BMC" for product "Control-M" and version " >= 9.0.21.0 < 9.0.21.201" | en |
Affected
|