Pivotal Software
pivotal_software
144 CVEs • 50 products
Products (50)
Click to collapseToggle
Products (50)
Click to collapse
CVEs (144)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal Software 2Broker Api On Demand Services SdkNov 21, 2024 Nov 19, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with differen...Show more |
1Pivotal Software 1Credhub Service Broker Nov 21, 2024 Nov 13, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify...Show more |
1Pivotal Software 1Bits Service Nov 21, 2024 Nov 9, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Nov 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation...Show more |
1Pivotal Software 1Spring Security Oauth Nov 21, 2024 Oct 18, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalation under certain con...Show more |
1Pivotal Software 1Pivotal Container Service Nov 21, 2024 Oct 5, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obt...Show more |
1Pivotal Software 1Cloud Foundry Log Cache Nov 21, 2024 Oct 5, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privi...Show more |
1Pivotal Software 2Cloudfoundry Uaa Cloudfoundry Uaa ReleaseNov 21, 2024 Oct 5, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Oct 5, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the c...Show more |
1Pivotal Software 1Pivotal Cloud Cache Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password. |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with ac...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 Sep 17, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to...Show more |
2Pivotal Software Vmware2Rabbitmq Java Client Spring Advanced Message Queuing ProtocolMar 27, 2025 Sep 14, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic w...Show more |
1Pivotal Software 1Cloud Foundry Elastic Runtime Nov 21, 2024 Sep 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote information disclosure. It was found that original mitigation configuration instr...Show more |
1Pivotal Software 1Cloud Foundry Uaa Nov 21, 2024 Jul 24, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid re...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 Jul 24, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when s...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jul 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker wit...Show more |
1Pivotal Software 1Operations Manager Nov 21, 2024 Jun 25, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to expl...Show more |
1Pivotal Software 2Cloud Foundry Uaa Cloud Foundry Uaa ReleaseNov 21, 2024 Jun 25, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form pa...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry DiegoNov 21, 2024 Jun 6, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a comp...Show more |