Delphix
Vendor:
First CVE: Oct 16, 2019 · Active for 6 years
5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 19% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Delphix over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2019
6 years ago
Most Recent CVE
Mar 6, 2024
874 days ago
CVE Severity & Scoring
Delphix5 CVEs
80%
20%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (80.0%)
High1 (20.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10453HIGH Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system | Oct 16, 2019 | 7.8 | 24 | NO | NO |
CVE-2023-40345MEDIUM Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credenti | Aug 16, 2023 | 6.5 | 19 | NO | NO |
CVE-2024-28161MEDIUM In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by defa | Mar 6, 2024 | 5.3 | 16 | NO | NO |
CVE-2023-40344MEDIUM A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | Aug 16, 2023 | 4.3 | 16 | NO | NO |
CVE-2024-28162MEDIUM In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) c | Mar 6, 2024 | 4.2 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Delphix
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.1 | 1 | 5.3 | 0.4% | 0 | 0 |