CVE-2024-1604

MEDIUM

BMC Control-m < 9.0.20.238 - IDOR

Title source: rule
STIX 2.1

Description

Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2024/03/CVE-2024-1604
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2024/03/CVE-2024-1604

Scores

CVSS v3 6.4
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
bmc/control-m 9.0.20 - 9.0.20.238
Published Mar 18, 2024
Tracked Since Feb 18, 2026