<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:51:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-04851</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-04851</link>
      <description>bdu:2022-04851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-04851</guid>
    </item>
    <item>
      <title>EUVD-2026-18651</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-18651</link>
      <description>EUVD-2026-18651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-18651</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36899</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36899</link>
      <description>&lt;p&gt;Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36899</guid>
    </item>
    <item>
      <title>GHSA-57f2-52wj-7vj6 — Agent-to-controller security bypass in Jenkins BMC Compuware ISPW Operations plugin</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-57f2-52wj-7vj6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.compuware.jenkins:compuware-ispw-operations&lt;/p&gt;
&lt;p&gt;BMC Compuware ISPW Operations Plugin defines a controller/agent message that retrieves Java system properties. BMC Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of the controller/agent message to agents. This allows attackers able to control agent processes to retrieve Java system properties. This vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.303/#upgrading-to-jenkins-lts-2-303-3). BMC Compuware ISPW Operations plugin 1.0.9 does not allow the affected controller/agent message to be submitted by agents for execution on the controller.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.compuware.jenkins:compuware-ispw-operations&lt;/p&gt;
&lt;p&gt;BMC Compuware ISPW Operations Plugin defines a controller/agent message that retrieves Java system properties. BMC Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of the controller/agent message to agents. This allows attackers able to control agent processes to retrieve Java system properties. This vulnerability is only exploitable in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.303/#upgrading-to-jenkins-lts-2-303-3). BMC Compuware ISPW Operations plugin 1.0.9 does not allow the affected controller/agent message to be submitted by agents for execution on the controller.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-57f2-52wj-7vj6</guid>
    </item>
    <item>
      <title>gsd-2022-36899</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36899</link>
      <description>gsd-2022-36899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36899</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0852 — Jenkins: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0852</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um einen Cross Site Scripting oder CSRF Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder Daten zu manipulieren&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Jenkins ausnutzen, um einen Cross Site Scripting oder CSRF Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen oder Daten zu manipulieren&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0852</guid>
    </item>
  </channel>
</rss>
