Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Credhub Service Broker HIGH 8.1
CVE-2018-15795

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A…

Fix: 1.1.0+
Fix from $1,950 2018-11-13
Bits Service HIGH 8.1
CVE-2018-15796

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a s…

Fix: 2.14.0+
Fix from $1,950 2018-11-09
Operations Manager HIGH 8.8
CVE-2018-15762

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior t…

Fix: 2.0.24 / 2.1.15+
Fix from $1,950 2018-11-02
Spring Security Oauth HIGH 8.1
CVE-2018-15758

Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported ve…

Fix: 2.0.16 / 2.1.3+
Fix from $1,950 2018-10-18
Pivotal Container Service HIGH 8.8
CVE-2018-15763

Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application lo…

Fix: 1.2+
Fix from $1,950 2018-10-05
Cloudfoundry Uaa CRITICAL 9.8
CVE-2018-11082

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remot…

Fix: 4.20.0 / 61.0+
Fix from $2,300 2018-10-05
Cloud Foundry Log Cache CRITICAL 9.8
CVE-2018-1264

Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has ga…

Fix: 1.1.1+
Fix from $2,300 2018-10-05
Operations Manager HIGH 8.8
CVE-2018-11081

Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Op…

Fix: 1.12.25 / 2.0.16+
Fix from $1,950 2018-10-05
Pivotal Application Service HIGH 8.8
CVE-2018-11086

Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug whi…

Fix: 2.0.21 / 2.1.13+
Fix from $1,950 2018-09-17
Pivotal Application Service HIGH 8.8
CVE-2018-11088

Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a …

Fix: 2.0.21 / 2.1.13+
Fix from $1,950 2018-09-17
Pivotal Cloud Cache HIGH 8.8
CVE-2018-1198

Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to …

Fix: 1.3.1+
Fix from $1,950 2018-09-17
Cloud Foundry Elastic Runtime MEDIUM 5.9
CVE-2016-0715

Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote informatio…

Fix: after 1.6.11
Fix from $1,600 2018-09-11
Cloud Foundry Uaa HIGH 7.5
CVE-2018-11047

Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, inc…

Fix: 4.5.7 / 4.7.6+
Fix from $1,950 2018-07-24
Pivotal Application Service MEDIUM 6.5
CVE-2018-11044

Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.…

Fix: 1.12.26 / 2.0.17+
Fix from $1,600 2018-07-24
Operations Manager MEDIUM 5.9
CVE-2018-11045

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Gene…

Fix: 1.12.22 / 2.0.15+
Fix from $1,600 2018-07-11
Operations Manager MEDIUM 6.5
CVE-2018-11046

Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An a…

Fix: 2.1.6+
Fix from $1,600 2018-06-25
Cloud Foundry Uaa MEDIUM 6.1
CVE-2018-11041

Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 exc…

Fix: 4.7.5 / 4.10.1+
Fix from $1,600 2018-06-25
Windows Stemcells MEDIUM 6.5
CVE-2018-1276

Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push…

Fix: 1200.17+
Fix from $1,600 2018-05-17
Cloud Foundry Uaa HIGH 7.2
CVE-2018-1262

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clien…

Fix: after 1.31.0
Fix from $1,950 2018-05-15
Spring Security Oauth CRITICAL 9.8
CVE-2018-1260EPSS 8%

Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai…

Fix: after 2.3.2
Fix from $2,300 2018-05-11
Greenplum Command Center HIGH 7.5
CVE-2018-1280

Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL …

Fix: 2.5.1+
Fix from $1,950 2018-05-11
Pivotal Application Service MEDIUM 6.5
CVE-2018-1278

Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an a…

Fix: 1.12.22 / 2.0.13+
Fix from $1,600 2018-05-11
Gemfire HIGH 7.5
CVE-2016-8220

Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application…

Fix: 1.6.5.0 / 1.7.1.0+
Fix from $1,950 2018-04-18
Bosh Cli HIGH 8.8
CVE-2018-1231

Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH…

Fix: 3.0.1+
Fix from $1,950 2018-03-27
Spring Batch Admin HIGH 8.8
CVE-2018-1230

Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicio…

Mitigation only
Fix from $1,950 2018-03-21
Spring Batch Admin MEDIUM 6.1
CVE-2018-1229

Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with netw…

Mitigation only
Fix from $1,600 2018-03-21
Windows Stemcells HIGH 8.5
CVE-2018-1197

In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata en…

Fix: 1200.14+
Fix from $1,950 2018-03-19
Gemfire For Pivotal Cloud Foundry CRITICAL 9.8
CVE-2016-9880

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and cou…

Fix: 1.6.5+
Fix from $2,300 2018-03-16
Pivotal Application Service MEDIUM 6.5
CVE-2018-1200

Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote fi…

Fix: 1.11.26 / 1.12.14+
Fix from $1,600 2018-03-16
Concourse HIGH 7.5
CVE-2018-1227

Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a D…

Mitigation only
Fix from $1,950 2018-03-13