CVE-2025-48709 Information

Description

An issue was discovered in BMC Control-M 9.0.21.300. When Control-M Server has a database connection it runs DBUStatus.exe frequently which then calls dbu_connection_details.vbs with the username password database hostname and port written in cleartext which can be seen in event and process logs in two separate locations.

Reference

https://bmc.com https://docs.bmc.com/xwiki/bin/view/Control-M-Orchestration/Control-M/ctm9021/Patches/Control-M-Server-PACTV-9-0-21-307/

CNNVD-202508-713 (Published: 2025-08-07)

Share on: