Skip to main content

Vendor/product archive

pivotal_software / operations_manager CVEs

Beta · best-effort

10 CVEs tagged to pivotal_software / operations_manager3 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2019-11292

Published Jan 9, 2020

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3790

Published Jun 6, 2019

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3776

Published Mar 7, 2019

Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cro…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15762

Published Nov 2, 2018

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a sc…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11081

Published Oct 5, 2018

Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config on…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11045

Published Jul 11, 2018

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedde…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11046

Published Jun 25, 2018

Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGI…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0897

Published Sep 18, 2016

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecif…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0883

Published Sep 18, 2016

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote att…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1