CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal Software 1Operations Manager Jun 17, 2026 Jan 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide...Show more |
1Pivotal Software 3Application Service Cloud Foundry UaaOperations ManagerJun 17, 2026 Aug 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' an...Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Jun 6, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration....Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Mar 7, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Nov 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Oct 5, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the c...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jul 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker wit...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jun 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to expl...Show more |
1Pivotal Software 1Operations Manager May 6, 2026 Sep 18, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors. |
1Pivotal Software 1Operations Manager May 6, 2026 Sep 18, 2016 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication b...Show more |