← Back

Pivotal Software

pivotal_software

144 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Rabbitmq
rabbitmq
Cloud Foundry
cloud_foundry
Concourse
concourse
Login Server
login-server
Spring Batch
spring_batch
Greenplum
greenplum
Grootfs
grootfs
Cf Deployment
cf-deployment
Spring Ldap
spring-ldap
Bosh Cli
bosh_cli
Gemfire
gemfire
Bits Service
bits_service
Broker Api
broker_api

CVEs (144)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pivotal Software
1Cloud Foundry Uaa
Jun 17, 2026
Jul 18, 2019
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
1Pivotal Software
1Cloud Foundry Uaa Release
Jun 17, 2026
Jul 11, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all ot...Show more
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.Show less
1Pivotal Software
1Cloud Foundry Uaa Release
Jun 17, 2026
Jun 19, 2019
N/A· v4
8.8 HIGH· v3
4.3 MEDIUM· v2
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private co...Show more
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account.Show less
2Oracle
Pivotal Software
2Banking Corporate Lending
Spring Security Oauth
Jun 17, 2026
Jun 12, 2019
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an...Show more
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the redirect_uri parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code.Show less
1Pivotal Software
1Operations Manager
Jun 17, 2026
Jun 6, 2019
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration....Show more
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.Show less
1Pivotal Software
1Spring Data Java Persistance Api
Jun 17, 2026
Jun 3, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONT...Show more
This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONTAINING could return more results than anticipated when a maliciously crafted example value is supplied.Show less
1Pivotal Software
1Spring Data Java Persistence Api
Jun 17, 2026
May 6, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated...Show more
This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated when a maliciously crafted query parameter value is supplied. Also, LIKE expressions in manually defined queries could return unexpected results if the parameter values bound did not have escaped reserved characters properly.Show less
1Pivotal Software
1Application Service
Jun 17, 2026
Apr 24, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user coul...Show more
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.Show less
1Pivotal Software
1Concourse
Jun 17, 2026
Apr 1, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the atta...Show more
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.Show less
2Oracle
Pivotal Software
2Banking Corporate Lending
Spring Security Oauth
Jun 17, 2026
Mar 7, 2019
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak...Show more
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicious user or attacker can craft a request to the authorization endpoint using the authorization code grant type, and specify a manipulated redirection URI via the "redirect_uri" parameter. This can cause the authorization server to redirect the resource owner user-agent to a URI under the control of the attacker with the leaked authorization code. This vulnerability exposes applications that meet all of the following requirements: Act in the role of an Authorization Server (e.g. @EnableAuthorizationServer) and uses the DefaultRedirectResolver in the AuthorizationEndpoint. This vulnerability does not expose applications that: Act in the role of an Authorization Server and uses a different RedirectResolver implementation other than DefaultRedirectResolver, act in the role of a Resource Server only (e.g. @EnableResourceServer), act in the role of a Client only (e.g. @EnableOAuthClient).Show less
1Pivotal Software
1Application Service
Jun 17, 2026
Mar 7, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthent...Show more
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's DNS record could intercept access tokens sent to the Cloud Controller, giving the attacker access to the user's resources in the Cloud ControllerShow less
1Pivotal Software
1Operations Manager
Jun 17, 2026
Mar 7, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote...Show more
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.Show less
1Pivotal Software
1Spring Batch
Jun 17, 2026
Jan 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
2Oracle
Pivotal Software
3Financial Services Analytical Applications Infrastructure
Flexcube Private BankingSpring Web Services
Jun 17, 2026
Jan 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
1Pivotal Software
1Concourse
Jun 17, 2026
Jan 12, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authen...Show more
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.Show less
1Pivotal Software
1Concourse
Nov 21, 2024
Dec 19, 2018
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an...Show more
Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access token in Concourse.Show less
1Pivotal Software
1Cloud Foundry Uaa Release
Nov 21, 2024
Dec 13, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authen...Show more
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.Show less
1Pivotal Software
1Rabbitmq
Nov 21, 2024
Dec 10, 2018
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the networ...Show more
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.Show less
1Pivotal Software
1Cloud Foundry Nfs Volume
Nov 21, 2024
Dec 5, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user w...Show more
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH can obtain the admin credentials for the Cloud Foundry Platform through the logs of the NFS volume deploy errand.Show less
1Pivotal Software
2Cloud Foundry Uaa
Cloudfoundry Uaa Release
Nov 21, 2024
Nov 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a co...Show more
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.Show less