Missing Authorization in Compuware Source Code Download for Endevor, PDS, and ISPW - CVE-2022-36896

 

Missing Authorization in Compuware Source Code Download for Endevor, PDS, and ISPW - CVE-2022-36896

Published: July 28, 2022


Vulnerability identifier: #VU65869
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36896
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to application does not properly impose security restrictions. A remote user can enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.


Affected software

Compuware Source Code Download for Endevor, PDS, and ISPW

How to mitigate CVE-2022-36896

Install updates from vendor's website.

Compuware Source Code Download for Endevor, PDS, and ISPW - update to 2.0.13

External References

Related Security Bulletins