Pivotal Software Operations Manager 2.3.5

CPE Details

Pivotal Software Operations Manager 2.3.5
2.3.5
2019-05-30
19h03 +00:00
2019-05-30
19h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pivotal_software:operations_manager:2.3.5:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

operations_manager

Version

2.3.5

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-11270 2019-08-05 16h21 +00:00 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
7.5
High
CVE-2019-3790 2019-06-06 19h16 +00:00 The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.
6.1
Medium
CVE-2019-3776 2019-03-07 19h00 +00:00 Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.
7.2
High