CVE-2025-48709

LOW

BMC Control-M/Server 9.0.21.300 - Info Disclosure

Title source: llm
STIX 2.1

Description

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, it runs 'DBUStatus.exe' frequently, which then calls 'dbu_connection_details.vbs' with the username, password, database hostname, and port written in cleartext, which can be seen in event and process logs in two separate locations. Fixed in PACTV.9.0.21.307.

Scores

CVSS v3 3.8
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-214 CWE-532 CWE-522
Status published
Products (1)
bmc/control-m\/server 9.0.21.300
Published Aug 07, 2025
Tracked Since Feb 18, 2026