VendorsPivotal Softwarepivotal_application_serviceall versions
Vulnerabilities

Pivotal Software Pivotal Application Service

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-11280
Privilege escalation through the invitations service
Published 2019-09-20 · Modified
8.8EPSS 0.015
CVE-2018-11086
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.
Published 2018-09-17 · Modified
8.8EPSS 0.010
CVE-2018-11088
Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.
Published 2018-09-17 · Modified
8.8EPSS 0.010
CVE-2018-1200
Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links.
Published 2018-03-16 · Modified
6.5EPSS 0.013
CVE-2018-1278
Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.
Published 2018-05-11 · Modified
6.5EPSS 0.012
CVE-2018-11044
Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.
Published 2018-07-24 · Modified
6.5EPSS 0.007
CVE-2019-11275
CSV Injection in usage report downloaded from Pivotal Application Manager
Published 2019-10-01 · Modified
4.3EPSS 0.011