CVE-2022-36899: High severity jenkins compuware ispw operations vulnerability
Published Jul 27, 2022
·Updated
Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
Affected Software
3 affected components
Jenkins Compuware Ispw Operations Jenkins<1.0.9
Jenkins Jenkins<=2.303.2
Jenkins Jenkins<=2.318
Event History
Jul 27, 2022
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
Description
Frequently Asked Questions
1
What is CVE-2022-36899?
CVE-2022-36899 is a vulnerability in Jenkins Compuware ISPW Operations Plugin that allows attackers to retrieve Java system properties by executing controller/agent messages.
2
How severe is CVE-2022-36899?
CVE-2022-36899 has a severity rating of 8.2, which is considered high.
3
Which versions of Jenkins Compuware ISPW Operations Plugin are affected by CVE-2022-36899?
Jenkins Compuware ISPW Operations Plugin versions 1.0.8 and earlier are affected by CVE-2022-36899.
4
How can an attacker exploit CVE-2022-36899?
An attacker with control over agent processes can exploit CVE-2022-36899 to retrieve Java system properties.
5
Is Jenkins Jenkins LTS version vulnerable to CVE-2022-36899?
No, Jenkins Jenkins LTS versions up to 2.303.2 are not vulnerable to CVE-2022-36899.