Vulnerability Description
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configuration is set to the non-default setting "use_openssl=n"; * Control-M/Agent 9.0.21 and 9.0.22: Agent router configuration uses the non-default settings "JAVA_AR=N" and "use_openssl=n"
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000441972
- https://bmcapps.my.site.com/casemgmt/sc_KnowledgeArticle?sfdcid=000442099
FAQ
What is CVE-2025-55118?
CVE-2025-55118 is a vulnerability with a CVSS score of 8.9 (HIGH). Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases: * Control-M/Agent 9.0.20: SSL/TLS configura...
How severe is CVE-2025-55118?
CVE-2025-55118 has been rated HIGH with a CVSS base score of 8.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55118?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.