Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.1
CVE-2018-15795
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A…
Credhub Service Broker
1.1.0+
HIGH 8.1
CVE-2018-15796
Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a s…
Bits Service
2.14.0+
HIGH 8.8
CVE-2018-15762
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior t…
Operations Manager
2.0.24 / 2.1.15+
HIGH 8.1
CVE-2018-15758
Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported ve…
Spring Security Oauth
2.0.16 / 2.1.3+
HIGH 8.8
CVE-2018-15763
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application lo…
Pivotal Container Service
1.2+
CRITICAL 9.8
CVE-2018-11082
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remot…
Cloudfoundry Uaa
4.20.0 / 61.0+
CRITICAL 9.8
CVE-2018-1264
Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has ga…
Cloud Foundry Log Cache
1.1.1+
HIGH 8.8
CVE-2018-11081
Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Op…
Operations Manager
1.12.25 / 2.0.16+
HIGH 8.8
CVE-2018-11086
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug whi…
Pivotal Application Service
2.0.21 / 2.1.13+
HIGH 8.8
CVE-2018-11088
Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a …
Pivotal Application Service
2.0.21 / 2.1.13+
HIGH 8.8
CVE-2018-1198
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to …
Pivotal Cloud Cache
1.3.1+
MEDIUM 5.9
CVE-2016-0715
Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vulnerable to a remote informatio…
Cloud Foundry Elastic Runtime
after 1.6.11
HIGH 7.5
CVE-2018-11047
Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, inc…
Cloud Foundry Uaa
4.5.7 / 4.7.6+
MEDIUM 6.5
CVE-2018-11044
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.…
Pivotal Application Service
1.12.26 / 2.0.17+
MEDIUM 5.9
CVE-2018-11045
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Gene…
Operations Manager
1.12.22 / 2.0.15+
MEDIUM 6.5
CVE-2018-11046
Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An a…
Operations Manager
2.1.6+
MEDIUM 6.1
CVE-2018-11041
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 exc…
Cloud Foundry Uaa
4.7.5 / 4.10.1+
MEDIUM 6.5
CVE-2018-1276
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push…
Windows Stemcells
1200.17+
HIGH 7.2
CVE-2018-1262
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clien…
Cloud Foundry Uaa
after 1.31.0
CRITICAL 9.8
CVE-2018-1260EPSS 8%
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contai…
Spring Security Oauth
after 2.3.2
HIGH 7.5
CVE-2018-1280
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL …
Greenplum Command Center
2.5.1+
MEDIUM 6.5
CVE-2018-1278
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an a…
Pivotal Application Service
1.12.22 / 2.0.13+
HIGH 7.5
CVE-2016-8220
Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application…
Gemfire
1.6.5.0 / 1.7.1.0+
HIGH 8.8
CVE-2018-1231
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH…
Bosh Cli
3.0.1+
HIGH 8.8
CVE-2018-1230
Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicio…
Spring Batch Admin
Mitigation only
MEDIUM 6.1
CVE-2018-1229
Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with netw…
Spring Batch Admin
Mitigation only
HIGH 8.5
CVE-2018-1197
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata en…
Windows Stemcells
1200.14+
CRITICAL 9.8
CVE-2016-9880
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and cou…
Gemfire For Pivotal Cloud Foundry
1.6.5+
MEDIUM 6.5
CVE-2018-1200
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote fi…
Pivotal Application Service
1.11.26 / 1.12.14+
HIGH 7.5
CVE-2018-1227
Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a D…
Concourse
Mitigation only