Skip to content

CVE-2023-32263 | Dimensions CM

A potential vulnerability has been identified in the Micro Focus Dimensions CM Plugin for Jenkins. The vulnerability could be exploited to retrieve a login certificate if an authenticated user is duped into using an attacker-controlled Dimensions CM server. This vulnerability only applies when the Jenkins plugin is configured to use login certificate credentials. https://www.jenkins.io/security/advisory/2023-06-14/ .This CVE has a CVSS3.1 score of 2.6 and a Base Severity of LOW.

InfoDetails
CVE IDCVE-2023-32263
CVE StatePUBLISHED
BaseScore2.6
BaseSeverityLOW
VectorStringCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
VersionNA

References for CVE-2023-32263 :
https://plugins.jenkins.io/dimensionsscm/
https://portal.microfocus.com/s/article/KM000019293

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)HIGH
PrivilegesRequired(PR)LOW
UserInteraction(UI)REQUIRED
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)NONE
Integrity(I)NONE