CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal Software 1Application Service Jun 17, 2026 Aug 19, 2019 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via S...Show more |
1Pivotal Software 3Application Service Cloud Foundry UaaOperations ManagerJun 17, 2026 Aug 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' an...Show more |
1Pivotal Software 1Application Service Jun 17, 2026 Apr 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user coul...Show more |
1Pivotal Software 1Application Service Jun 17, 2026 Mar 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthent...Show more |