CVE-2024-1606

MEDIUM

BMC Control-M 9.0.20-9.0.20.237 and 9.0.21-9.0.21.199 - Authenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker. Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2024/03/CVE-2024-1604
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2024/03/CVE-2024-1604

Scores

CVSS v3 4.6
EPSS 0.0043
EPSS Percentile 34.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
bmc/control-m 9.0.20 - 9.0.20.238
Published Mar 18, 2024
Tracked Since Feb 18, 2026