Vulnerability index

Browse CVEs

85 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-1192 In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x version… Cloud Foundry Uaa 1.7 / 4.5.5+ Fix from $1,9502018-02-01 CRITICAL 9.8 CVE-2017-8045 In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c… Spring Advanced Message Queuing Protocol Mitigation only Fix from $2,3002017-11-27 HIGH 8.8 CVE-2017-8038 In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation… Credhub Release Mitigation only Fix from $1,9502017-11-27 HIGH 7.5 CVE-2017-14390 In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locat… Cf Deployment Mitigation only Fix from $1,9502017-11-27 HIGH 7.8 CVE-2017-14388 Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the groo… Grootfs Mitigation only Fix from $1,9502017-11-13 MEDIUM 6.6 CVE-2017-8032 In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to … Cloud Foundry Uaa after 263 Fix from $1,6002017-07-10 CRITICAL 9.8 CVE-2017-2773 An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23… Cloud Foundry Elastic Runtime Mitigation only Fix from $2,3002017-06-13 CRITICAL 9.8 CVE-2017-4955 An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28… Cloud Foundry Elastic Runtime Mitigation only Fix from $2,3002017-06-13 HIGH 8.8 CVE-2017-4959 An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deploy… Cloud Foundry Elastic Runtime Mitigation only Fix from $1,9502017-06-13 HIGH 8.1 CVE-2017-4963 An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.… Cloud Foundry Cf Release after 252 Fix from $1,9502017-06-13 CRITICAL 9.8 CVE-2016-5006 The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user cred… Cloud Foundry after 238.0 Fix from $2,3002017-05-02 MEDIUM 5.9 CVE-2016-5016 Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Piv… Cloud Foundry 1.6.35 / 1.7.13+ Fix from $1,6002017-04-24 CRITICAL 9.8 CVE-2016-9885 An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, … Gemfire For Pivotal Cloud Foundry Mitigation only Fix from $2,3002017-01-06 HIGH 7.4 CVE-2016-6657 An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply … Cloud Foundry Ops Manager Mitigation only Fix from $1,9502016-12-16 HIGH 7.2 CVE-2016-6656 An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary… Greenplum after 4.3.9.1 Fix from $1,9502016-12-16 HIGH 7.5 CVE-2016-6653 The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information … Cloud Foundry Cf Mysql Mitigation only Fix from $1,9502016-10-06 MEDIUM 5.6 CVE-2016-6652 SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository … Spring Data Jpa after 1.9.4 Fix from $1,6002016-10-05 HIGH 7.5 CVE-2016-0929 The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might al… Rabbitmq Mitigation only Fix from $1,9502016-09-18 MEDIUM 6.1 CVE-2016-0927 Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web scr… Cloud Foundry Elastic Runtime Mitigation only Fix from $1,6002016-09-18 MEDIUM 6.1 CVE-2016-0926 Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows r… Cloud Foundry Elastic Runtime 1.6.32 / 1.7.8+ Fix from $1,6002016-09-18 CRITICAL 9.8 CVE-2016-0897 Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for… Operations Manager after 1.6.16 Fix from $2,3002016-09-18 HIGH 7.3 CVE-2016-0896 Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, w… Cloud Foundry Elastic Runtime after 1.6.33 Fix from $1,9502016-09-18 CRITICAL 9.8 CVE-2016-0883 Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installa… Operations Manager after 1.5.13 Fix from $2,3002016-09-18 MEDIUM 5.0 CVE-2014-3578EPSS 6% Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files v… Spring Framework 3.2.9 / 4.0.5+ Fix from $1,6002015-02-19 MEDIUM 5.0 CVE-2014-9494 RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header. Rabbitmq after 3.3.5 Fix from $1,6002015-01-20