cve/2024/CVE-2024-1604.md
2025-09-29 16:08:36 +00:00

20 lines
1.1 KiB
Markdown
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

### [CVE-2024-1604](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1604)
![](https://img.shields.io/static/v1?label=Product&message=Control-M&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=9.0.20%3C%209.0.20.238%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-639%20Authorization%20Bypass%20Through%20User-Controlled%20Key&color=brighgreen)
### Description
Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate.Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/DojoSecurity/DojoSecurity
- https://github.com/NaInSec/CVE-LIST
- https://github.com/afine-com/research