CVE-2024-1604

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*
cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*

History

06 Mar 2025, 14:25

Type Values Removed Values Added
CPE cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*
First Time Bmc control-m
Bmc
CWE CWE-639
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
References () https://www.bmc.com/it-solutions/control-m.html - () https://www.bmc.com/it-solutions/control-m.html - Product
References () https://cert.pl/en/posts/2024/03/CVE-2024-1604 - () https://cert.pl/en/posts/2024/03/CVE-2024-1604 - Third Party Advisory
References () https://cert.pl/posts/2024/03/CVE-2024-1604 - () https://cert.pl/posts/2024/03/CVE-2024-1604 - Third Party Advisory

10 Oct 2024, 16:15

Type Values Removed Values Added
Summary Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201. Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

18 Mar 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-18 10:15

Updated : 2025-03-06 14:25


NVD link : CVE-2024-1604

Mitre link : CVE-2024-1604


JSON object : View

Products Affected

bmc

  • control-m
CWE
CWE-639

Authorization Bypass Through User-Controlled Key