Vulnerabilities > Pivotal Software > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-17 CVE-2018-1198 Information Exposure Through Log Files vulnerability in Pivotal Software Pivotal Cloud Cache
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs.
network
low complexity
pivotal-software CWE-532
8.8
2018-09-17 CVE-2018-11088 Unspecified vulnerability in Pivotal Software Pivotal Application Service
Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges.
network
low complexity
pivotal-software
8.8
2018-09-17 CVE-2018-11086 Unspecified vulnerability in Pivotal Software Pivotal Application Service
Pivotal Usage Service in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges.
network
low complexity
pivotal-software
8.8
2018-07-24 CVE-2018-11047 Incorrect Authorization vulnerability in Pivotal Software Cloud Foundry UAA
Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid refresh token in lieu of an access token.
network
low complexity
pivotal-software CWE-863
7.5
2018-06-06 CVE-2018-1265 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers.
network
low complexity
pivotal-software cloudfoundry CWE-434
7.2
2018-05-15 CVE-2018-1262 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation.
network
low complexity
pivotal-software cloudfoundry
7.2
2018-05-11 CVE-2018-1280 SQL Injection vulnerability in Pivotal Software Greenplum Command Center
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability.
network
low complexity
pivotal-software CWE-89
7.5
2018-05-11 CVE-2018-1259 XXE vulnerability in multiple products
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference expansion.
network
low complexity
pivotal-software xmlbeam CWE-611
7.5
2018-05-11 CVE-2018-1258 Incorrect Authorization vulnerability in multiple products
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security.
8.8
2018-04-18 CVE-2018-1274 Allocation of Resources Without Limits or Throttling vulnerability in Pivotal Software Spring Data Commons and Spring Data Rest
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation.
network
low complexity
pivotal-software CWE-770
7.5