VYPR
Vendor

Black Duck

Products
4
CVEs
5
Across products
7
Status
Private

Products

4

Recent CVEs

5
  • CVE-2026-1496CriMar 27, 2026
    risk 0.60cvss —epss 0.00

    Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can…

  • CVE-2026-76055HigAug 24, 2026
    risk 0.49cvss —epss 0.00

    Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.7 allows an actor able to create a file within the scanned build directory to execute operating system commands as the account running the…

  • CVE-2026-76054HigAug 24, 2026
    risk 0.46cvss —epss 0.00

    Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by…

  • CVE-2025-0504MedNov 21, 2025
    risk 0.35cvss 5.4epss 0.00

    Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with the scoped Project Manager user role with the Global User Read access permission enabled access to certain Project Administrator functionalities which should…

  • CVE-2026-8339HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized…