Authentication Bypass in Control-M/Agent by BMC Software
CVE-2025-55109
What is CVE-2025-55109?
An authentication bypass vulnerability in the Control-M/Agent allows remote attackers to circumvent authentication processes when using empty or default keystores. This issue is especially concerning for users of unsupported versions 9.0.18 to 9.0.20, where expired fallback certificates may inadvertently trust unauthorized entities. By leveraging a null or default PKCS#12 keystore, attackers can exploit the hardcoded certificates included in these versions, leading to potential unauthorized access. It's critical for users to be aware of the trusted certificates that could expose client authentication processes to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Control-M/Agent 9.0.21
Control-M/Agent 9.0.20
Control-M/Agent 9.0.19
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
