{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-28T14:26:46.235","vulnerabilities":[{"cve":{"id":"CVE-2024-1604","sourceIdentifier":"cvd@cert.pl","published":"2024-03-18T10:15:19.900","lastModified":"2026-06-17T07:04:37.393","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users to read and make unauthorized changes to any reports available within the application, even without proper permissions. The attacker must know the unique identifier of the report they want to manipulate.\n\n\n\n\n\n\n\nFix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.201."},{"lang":"es","value":"La autorización inadecuada en el módulo de creación y gestión de informes de las ramas 9.0.20 y 9.0.21 de BMC Control-M permite a los usuarios registrados leer y realizar cambios no autorizados en cualquier informe disponible dentro de la aplicación, incluso sin los permisos adecuados. El atacante debe conocer el identificador único del informe que quiere manipular. La solución para la rama 9.0.20 se lanzó en la versión 9.0.20.238. La solución para la rama 9.0.21 se lanzó en la versión 9.0.21.201."}],"affected":[{"source":"cvd@cert.pl","affectedData":[{"vendor":"BMC","product":"Control-M","defaultStatus":"unknown","versions":[{"version":"9.0.20","lessThan":"9.0.20.238","versionType":"custom","status":"affected"},{"version":"9.0.21","lessThan":"9.0.21.201","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"bmc","product":"control-m","defaultStatus":"unknown","cpes":["cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*"],"versions":[{"version":"9.0.20","lessThan":"9.0.20.238","versionType":"custom","status":"affected"},{"version":"9.0.21","lessThan":"9.0.21.201","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cvd@cert.pl","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-21T20:14:22.181539Z","id":"CVE-2024-1604","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cvd@cert.pl","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.20","versionEndExcluding":"9.0.20.238","matchCriteriaId":"87B57AF2-7AB2-48C3-A85B-A918033C70AF"},{"vulnerable":true,"criteria":"cpe:2.3:a:bmc:control-m:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.21","versionEndExcluding":"9.0.21.201","matchCriteriaId":"8F86D69B-93E8-42A3-8D24-CDB59F33A388"}]}]}],"references":[{"url":"https://cert.pl/en/posts/2024/03/CVE-2024-1604","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2024/03/CVE-2024-1604","source":"cvd@cert.pl","tags":["Third Party Advisory"]},{"url":"https://www.bmc.com/it-solutions/control-m.html","source":"cvd@cert.pl","tags":["Product"]},{"url":"https://cert.pl/en/posts/2024/03/CVE-2024-1604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://cert.pl/posts/2024/03/CVE-2024-1604","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.bmc.com/it-solutions/control-m.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"]}]}}]}