Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2018-1192
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x version…
Cloud Foundry Uaa
1.7 / 4.5.5+
CRITICAL 9.8
CVE-2017-8045
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being c…
Spring Advanced Message Queuing Protocol
Mitigation only
HIGH 8.8
CVE-2017-8038
In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation…
Credhub Release
Mitigation only
HIGH 7.5
CVE-2017-14390
In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locat…
Cf Deployment
Mitigation only
HIGH 7.8
CVE-2017-14388
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the groo…
Grootfs
Mitigation only
MEDIUM 6.6
CVE-2017-8032
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to …
Cloud Foundry Uaa
after 263
CRITICAL 9.8
CVE-2017-2773
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23…
Cloud Foundry Elastic Runtime
Mitigation only
CRITICAL 9.8
CVE-2017-4955
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28…
Cloud Foundry Elastic Runtime
Mitigation only
HIGH 8.8
CVE-2017-4959
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deploy…
Cloud Foundry Elastic Runtime
Mitigation only
HIGH 8.1
CVE-2017-4963
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.…
Cloud Foundry Cf Release
after 252
CRITICAL 9.8
CVE-2016-5006
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user cred…
Cloud Foundry
after 238.0
MEDIUM 5.9
CVE-2016-5016
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Piv…
Cloud Foundry
1.6.35 / 1.7.13+
CRITICAL 9.8
CVE-2016-9885
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, …
Gemfire For Pivotal Cloud Foundry
Mitigation only
HIGH 7.4
CVE-2016-6657
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply …
Cloud Foundry Ops Manager
Mitigation only
HIGH 7.2
CVE-2016-6656
An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary…
Greenplum
after 4.3.9.1
HIGH 7.5
CVE-2016-6653
The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information …
Cloud Foundry Cf Mysql
Mitigation only
MEDIUM 5.6
CVE-2016-6652
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository …
Spring Data Jpa
after 1.9.4
HIGH 7.5
CVE-2016-0929
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might al…
Rabbitmq
Mitigation only
MEDIUM 6.1
CVE-2016-0927
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web scr…
Cloud Foundry Elastic Runtime
Mitigation only
MEDIUM 6.1
CVE-2016-0926
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows r…
Cloud Foundry Elastic Runtime
1.6.32 / 1.7.8+
CRITICAL 9.8
CVE-2016-0897
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for…
Operations Manager
after 1.6.16
HIGH 7.3
CVE-2016-0896
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, w…
Cloud Foundry Elastic Runtime
after 1.6.33
CRITICAL 9.8
CVE-2016-0883
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installa…
Operations Manager
after 1.5.13
MEDIUM 5.0
CVE-2014-3578EPSS 6%
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files v…
Spring Framework
3.2.9 / 4.0.5+
MEDIUM 5.0
CVE-2014-9494
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Rabbitmq
after 3.3.5