<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:32:56.748584+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-04851</id>
    <title>bdu:2022-04851</title>
    <updated>2026-10-03T03:32:56.824782+00:00</updated>
    <content>bdu:2022-04851</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-04851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-18651</id>
    <title>EUVD-2026-18651</title>
    <updated>2026-10-03T03:32:56.824819+00:00</updated>
    <content>EUVD-2026-18651</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-18651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36899</id>
    <title>fkie_cve-2022-36899</title>
    <updated>2026-10-03T03:32:56.824834+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-57f2-52wj-7vj6</id>
    <title>GHSA-57f2-52wj-7vj6 — Agent-to-controller security bypass in Jenkins BMC Compuware ISPW Operations plugin</title>
    <updated>2026-10-03T03:32:56.824863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: com.compuware.jenkins:compuware-ispw-operations</p>
<p>BMC Compuware ISPW Operations Plugin defines a controller/agent message that retrieves Java system properties. BMC Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of the controller/agent message to agents. This allows attackers able to control agent processes to retrieve Java system properties. This vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.303/#upgrading-to-jenkins-lts-2-303-3). BMC Compuware ISPW Operations plugin 1.0.9 does not allow the affected controller/agent message to be submitted by agents for execution on the controller.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-57f2-52wj-7vj6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36899</id>
    <title>gsd-2022-36899</title>
    <updated>2026-10-03T03:32:56.824890+00:00</updated>
    <content>gsd-2022-36899</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0852</id>
    <title>WID-SEC-W-2022-0852 — Jenkins: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:32:56.824902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um einen Cross Site Scripting oder CSRF Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder Daten zu manipulieren</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0852"/>
  </entry>
</feed>
