VendorsPivotal Softwareoperations_managerall versions
Vulnerabilities

Pivotal Software Operations Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2016-0897
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.
Published 2016-09-18 · Modified
9.8EPSS 0.015
CVE-2016-0883
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
Published 2016-09-18 · Modified
9.8EPSS 0.009
CVE-2018-15762
Pivotal Operations Manager gives all users heightened privileges
Published 2018-11-02 · Modified
9.0EPSS 0.011
CVE-2018-11081
Pivotal Operations Manager UAA config - temp Ram Disk
Published 2018-10-05 · Modified
8.8EPSS 0.014
CVE-2019-11292
Pivotal Ops Manager logs query parameters in tomcat access file
Published 2020-01-08 · Modified
8.8EPSS 0.011
CVE-2019-11270
UAA clients.write vulnerability
Published 2019-08-05 · Modified
7.5EPSS 0.011
CVE-2019-3776
Reflected XSS in Pivotal Operations Manager
Published 2019-03-07 · Modified
7.2EPSS 0.008
CVE-2018-11046
Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities may be able to impact Operations Manager
Published 2018-06-25 · Modified
6.5EPSS 0.009
CVE-2019-3790
Ops Manager uaa client issues tokens after refresh token expiration
Published 2019-06-06 · Modified
6.1EPSS 0.007
CVE-2018-11045
Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.
Published 2018-07-11 · Modified
5.9EPSS 0.009