CVE-2025-55113
CRITICALDescription
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL byte encountered in the email address referenced in the client certificate. An attacker could bypass configured ACLs by using a specially crafted certificate.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| bmc | control-m\/agent |
References
Frequently Asked Questions
What is CVE-2025-55113? +
How severe is CVE-2025-55113? +
What products are affected by CVE-2025-55113? +
How do I check if I'm vulnerable to CVE-2025-55113? +
Related Vulnerabilities
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By …
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary …
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up …
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, …
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when …
An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted …