Pivotal Software

Operations Manager

10 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Published 09.01.2020 00:15:09
  • Last modified 21.11.2024 04:20:51

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credential...

  • EPSS 0.23%
  • Published 05.08.2019 17:15:10
  • Last modified 21.11.2024 04:20:49

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrar...

  • EPSS 0.06%
  • Published 06.06.2019 19:29:00
  • Last modified 21.11.2024 04:42:32

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user c...

  • EPSS 0.19%
  • Published 07.03.2019 18:29:00
  • Last modified 21.11.2024 04:42:31

Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince...

  • EPSS 0.22%
  • Published 02.11.2018 22:29:00
  • Last modified 21.11.2024 03:51:25

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who ...

  • EPSS 0.16%
  • Published 05.10.2018 21:29:00
  • Last modified 21.11.2024 03:42:38

Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A r...

  • EPSS 0.3%
  • Published 11.07.2018 20:29:00
  • Last modified 21.11.2024 03:42:33

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact versi...

  • EPSS 0.34%
  • Published 25.06.2018 15:29:00
  • Last modified 21.11.2024 03:42:33

Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilit...

  • EPSS 0.48%
  • Published 18.09.2016 02:59:02
  • Last modified 12.04.2025 10:46:40

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.

  • EPSS 0.16%
  • Published 18.09.2016 02:59:00
  • Last modified 12.04.2025 10:46:40

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this...