Jenkins Compuware ISPW Operations for Jenkins

CPE Details

Jenkins Compuware ISPW Operations for Jenkins
-
2022-08-02
09h13 +00:00
2022-08-02
12h12 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:jenkins:compuware_ispw_operations:-:*:*:*:*:jenkins:*:*

Informations

Vendor

jenkins

Product

compuware_ispw_operations

Version

-

Target Software

jenkins

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-36899 2022-07-27 12h24 +00:00 Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
8.2
High
CVE-2022-36898 2022-07-27 12h24 +00:00 A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
4.3
Medium