← Back

Pivotal Software

pivotal_software

144 CVEs • 50 products

Products (50)

Click to collapse
Toggle
Rabbitmq
rabbitmq
Cloud Foundry
cloud_foundry
Concourse
concourse
Login Server
login-server
Spring Batch
spring_batch
Greenplum
greenplum
Grootfs
grootfs
Cf Deployment
cf-deployment
Spring Ldap
spring-ldap
Bosh Cli
bosh_cli
Gemfire
gemfire
Bits Service
bits_service
Broker Api
broker_api

CVEs (144)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pivotal Software
1Windows Stemcells
Nov 21, 2024
May 17, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the V...Show more
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials.Show less
2Cloudfoundry
Pivotal Software
3Cf Deployment
Cloud Foundry UaaCloud Foundry Uaa Release
Nov 21, 2024
May 15, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure...Show more
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.Show less
1Pivotal Software
1Greenplum Command Center
Nov 21, 2024
May 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database...Show more
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.Show less
1Pivotal Software
1Pivotal Application Service
Nov 21, 2024
May 11, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to...Show more
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.Show less
1Pivotal Software
1Spring Security Oauth
Nov 21, 2024
May 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker...Show more
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code execution when the resource owner is forwarded to the approval endpoint.Show less
4Broadcom
Pivotal SoftwareVmware+1 more
5Spring Data Commons
Spring Data CommonsSpring Data Rest+2 more
Jun 26, 2026
May 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML exte...Show more
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion. An unauthenticated remote malicious user can supply specially crafted request parameters against Spring Data's projection-based request payload binding to access arbitrary files on the system.Show less
5Netapp
OraclePivotal Software+2 more
42Agile Plm
Application Testing SuiteBig Data Discovery+39 more
Nov 21, 2024
May 11, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.Show less
3Broadcom
Pivotal SoftwareVmware
4Spring Data Commons
Spring Data CommonsSpring Data Rest+1 more
Jun 26, 2026
Apr 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user...Show more
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).Show less
1Pivotal Software
1Gemfire
Nov 21, 2024
Apr 18, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application inadvertently exposed WAN replication credentials at a public route.
5Apache
BroadcomOracle+2 more
6Financial Services Crime And Compliance Management Studio
IgniteSpring Data Commons+3 more
Jun 26, 2026
Apr 11, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remo...Show more
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.Show less
2Cloudfoundry
Pivotal Software
2Cf Release
Cloud Foundry Elastic Runtime
Nov 21, 2024
Mar 29, 2018
N/A· v4
9.6 CRITICAL· v3
4.0 MEDIUM· v2
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (...Show more
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.Show less
1Pivotal Software
1Bosh Cli
Nov 21, 2024
Mar 27, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to...Show more
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.Show less
1Pivotal Software
1Spring Batch Admin
Nov 21, 2024
Mar 21, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This issue has no...Show more
Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This issue has not been patched because Spring Batch Admin has reached end of life.Show less
1Pivotal Software
1Spring Batch Admin
Nov 21, 2024
Mar 21, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script th...Show more
Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has reached end of life.Show less
1Pivotal Software
1Windows Stemcells
Nov 21, 2024
Mar 19, 2018
N/A· v4
8.5 HIGH· v3
6.0 MEDIUM· v2
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged...Show more
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.Show less
1Pivotal Software
1Pivotal Application Service
Nov 21, 2024
Mar 16, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
1Pivotal Software
1Gemfire For Pivotal Cloud Foundry
Nov 21, 2024
Mar 16, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
1Pivotal Software
1Concourse
Nov 21, 2024
Mar 13, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain...Show more
Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project has been registered by an unknown actor, and is therefore no longer the official website for Concourse CI. The new official domain is concourse-ci.org. At approximately 4 am EDT on March 7, 2018 the Concourse OSS team began receiving reports that the Concourse domain was not responding. The Concourse OSS team discovered, upon investigation with both the original and the new domain registrars, that the originating domain registrar had made the domain available for purchase. This was done despite the domain being renewed by the Concourse OSS team through August 2018. For a customer to be affected, they would have needed to access a download from a "concourse-dot-ci" domain web site after March 6, 2018 18:00:00 EST. Accessing that domain is NOT recommended by Pivotal. Anyone who had been using that domain should immediately begin using the concourse-ci.org domain instead. Customers can also safely access Concourse software from the traditionally available locations on the Pivotal Network or GitHub.Show less
1Pivotal Software
4Cloud Foundry Cf Deployment
Cloud Foundry Cf ReleaseCloud Foundry Uaa+1 more
Nov 21, 2024
Feb 1, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45...Show more
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.Show less
2Pivotal Software
Vmware
3Spring Boot
Spring Data RestSpring Data Rest
Jun 26, 2026
Jan 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON...Show more
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.Show less