Filtered by vendor Bmc Subscriptions
Filtered by product Control-m/server Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-10539 1 Bmc 1 Control-m/server 2026-07-01 9 Critical
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.
CVE-2026-10538 1 Bmc 2 Control-m/enterprise Manager, Control-m/server 2026-07-01 8 High
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.