Pivotal Software
pivotal_software
144 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (144)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal Software 1Cloud Foundry Uaa Jun 17, 2026 Jul 18, 2019 N/A· v4 5.4 MEDIUM· v3 4.3 MEDIUM· v2 Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites. |
1Pivotal Software 1Cloud Foundry Uaa Release Jun 17, 2026 Jul 11, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all ot...Show more |
1Pivotal Software 1Cloud Foundry Uaa Release Jun 17, 2026 Jun 19, 2019 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private co...Show more |
2Oracle Pivotal Software2Banking Corporate Lending Spring Security OauthJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an...Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Jun 6, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration....Show more |
1Pivotal Software 1Spring Data Java Persistance Api Jun 17, 2026 Jun 3, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatcher.StringMatcher.STARTING, ExampleMatcher.StringMatcher.ENDING or ExampleMatcher.StringMatcher.CONT...Show more |
1Pivotal Software 1Spring Data Java Persistence Api Jun 17, 2026 May 6, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the predicates ‘startingWith’, ‘endingWith’ or ‘containing’ could return more results than anticipated...Show more |
1Pivotal Software 1Application Service Jun 17, 2026 Apr 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user coul...Show more |
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the atta...Show more |
2Oracle Pivotal Software2Banking Corporate Lending Spring Security OauthJun 17, 2026 Mar 7, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak...Show more |
1Pivotal Software 1Application Service Jun 17, 2026 Mar 7, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthent...Show more |
1Pivotal Software 1Operations Manager Jun 17, 2026 Mar 7, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote...Show more |
1Pivotal Software 1Spring Batch Jun 17, 2026 Jan 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |
2Oracle Pivotal Software3Financial Services Analytical Applications Infrastructure Flexcube Private BankingSpring Web ServicesJun 17, 2026 Jan 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authen...Show more |
1Pivotal Software 1Concourse Nov 21, 2024 Dec 19, 2018 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an...Show more |
1Pivotal Software 1Cloud Foundry Uaa Release Nov 21, 2024 Dec 13, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authen...Show more |
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the networ...Show more |
1Pivotal Software 1Cloud Foundry Nfs Volume Nov 21, 2024 Dec 5, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user w...Show more |
1Pivotal Software 2Cloud Foundry Uaa Cloudfoundry Uaa ReleaseNov 21, 2024 Nov 19, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a co...Show more |