CVE-2022-36900: High severity jenkins compuware zadviser api vulnerability
Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.
Other sources
Jenkins Compuware zAdviser API Plugin defines a controller/agent message that retrieves Java system properties.
Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of the controller/agent message to agents. This allows attackers able to control agent processes to retrieve Java system properties.
Compuware zAdviser API Plugin 1.0.4 does not allow the affected controller/agent message to be submitted by agents for execution on the controller.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36900?
The severity of CVE-2022-36900 is high with a score of 8.2.
How does Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier vulnerability work?
Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier allows execution of a controller/agent message to retrieve Java system properties, even by attackers who control agent processes.
Which versions of Jenkins Compuware zAdviser API Plugin are affected by CVE-2022-36900?
Jenkins Compuware zAdviser API Plugin versions up to and including 1.0.3 are affected by CVE-2022-36900.
How can I fix CVE-2022-36900?
To fix CVE-2022-36900, upgrade to version 1.0.4 of Jenkins Compuware zAdviser API Plugin.
Where can I find more information about CVE-2022-36900?
You can find more information about CVE-2022-36900 at the following references: [Openwall](http://www.openwall.com/lists/oss-security/2022/07/27/1), [Jenkins Security Advisory](https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2630), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-36900).