Vulnerabilities > Pivotal Software

DATE CVE VULNERABILITY TITLE RISK
2016-12-29 CVE-2016-9877 Improper Access Control vulnerability in multiple products
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7.
network
low complexity
pivotal-software vmware CWE-284
critical
9.8
2016-12-23 CVE-2016-6659 Improper Authentication vulnerability in multiple products
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
network
high complexity
pivotal-software cloudfoundry CWE-287
8.1
2016-12-16 CVE-2016-6657 Open Redirect vulnerability in Pivotal Software products
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components.
network
low complexity
pivotal-software CWE-601
7.4
2016-12-16 CVE-2016-6656 Command Injection vulnerability in Pivotal Software Greenplum
An issue was discovered in Pivotal Greenplum before 4.3.10.0.
network
low complexity
pivotal-software CWE-77
7.2
2016-12-09 CVE-2015-8786 Resource Management Errors vulnerability in multiple products
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
network
low complexity
oracle pivotal-software CWE-399
6.5
2016-10-06 CVE-2016-6653 Information Exposure vulnerability in Pivotal Software Cloud Foundry CF Mysql 27.0/28.0
The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information by reading syslog messages, as demonstrated by cleartext credentials.
network
low complexity
pivotal-software CWE-200
7.5
2016-10-05 CVE-2016-6652 SQL Injection vulnerability in Pivotal Software Spring Data JPA 1.10.2
SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.
network
high complexity
pivotal-software CWE-89
5.6
2016-09-30 CVE-2016-6651 Permissions, Privileges, and Access Controls vulnerability in multiple products
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allows remote authenticated users to gain privileges by leveraging possession of a token.
network
low complexity
pivotal-software cloudfoundry CWE-264
8.8
2016-09-30 CVE-2016-6637 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allow remote attackers to hijack the authentication of unspecified victims for requests that approve or deny a scope via a profile or authorize approval page.
network
low complexity
pivotal-software cloudfoundry CWE-352
critical
9.6
2016-09-30 CVE-2016-6636 Open Redirect vulnerability in multiple products
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 mishandles redirect_uri subdomains, which allows remote attackers to obtain implicit access tokens via a modified subdomain.
network
low complexity
pivotal-software cloudfoundry CWE-601
5.3