Cadence Vmanager Jenkins Cadence Vmanager

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Jenkins Cadence Vmanager.

By the Year

In 2025 there have been 3 vulnerabilities in Jenkins Cadence Vmanager. Cadence Vmanager did not have any published security vulnerabilities last year. That is, 3 more vulnerabilities have already been reported in 2025 as compared to last year.

Year Vulnerabilities Average Score
2025 3 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 5.40
2019 1 8.20

It may take a day or so for new Cadence Vmanager vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jenkins Cadence Vmanager Security Vulnerabilities

Jenkins Cadence vManager 4.0.1-286: Missing Permission Checks (Read/Overall)
CVE-2025-47887 - May 14, 2025

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

CSRF in Jenkins Cadence vManager Plugin <=4.0.1; auto redirect attacker URL
CVE-2025-47886 - May 14, 2025

A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.

Jenkins Cadence vManager Plugin <=4.0.0-282: vAPI Keys Unencrypted in config.xml
CVE-2025-31724 - April 02, 2025

Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips
CVE-2020-2243 5.4 - Medium - September 01, 2020

Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

XSS

Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.
CVE-2019-10446 8.2 - High - October 16, 2019

Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

Improper Certificate Validation

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Jenkins Cadence Vmanager or by Jenkins? Click the Watch button to subscribe.

Jenkins
Vendor

subscribe