Vulnerabilities > Pivotal Software > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-05-02 CVE-2016-5006 Information Exposure vulnerability in Pivotal Software Cloud Foundry and Cloud Foundry Elastic Runtime
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
network
low complexity
pivotal-software CWE-200
critical
9.8
2017-01-06 CVE-2016-9885 7PK - Security Features vulnerability in Pivotal Software Gemfire for Pivotal Cloud Foundry
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1.
network
low complexity
pivotal-software CWE-254
critical
9.8
2016-12-29 CVE-2016-9877 Improper Access Control vulnerability in multiple products
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7.
network
low complexity
pivotal-software vmware CWE-284
critical
9.8
2016-09-30 CVE-2016-6637 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allow remote attackers to hijack the authentication of unspecified victims for requests that approve or deny a scope via a profile or authorize approval page.
network
low complexity
pivotal-software cloudfoundry CWE-352
critical
9.6
2016-09-18 CVE-2016-0897 Cryptographic Issues vulnerability in Pivotal Software Operations Manager
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.
network
low complexity
pivotal-software CWE-310
critical
9.8
2016-09-18 CVE-2016-0883 Improper Authentication vulnerability in Pivotal Software Operations Manager
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
network
low complexity
pivotal-software CWE-287
critical
9.8