Vulnerability Database

318,275

Total vulnerabilities in the database

CVE-2025-55108

The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration).

NOTE: 

  • The vendor believes that this vulnerability only occurs when documented security best practices are not followed. BMC has always strongly recommended to use security best practices such as configuring SSL/TLS between Control-M Server and Agent.

  • The vendor notifies that Control-M/Agent is not impacted in Control-M SaaS

  • Published: Nov 5, 2025
  • Updated: Nov 19, 2025
  • CVE: CVE-2025-55108
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 10
  • AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CWEs: