Pivotal Software Operations Manager 2.0.7

CPE Details

Pivotal Software Operations Manager 2.0.7
2.0.7
2018-11-26
17h58 +00:00
2018-11-26
17h58 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:pivotal_software:operations_manager:2.0.7:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

operations_manager

Version

2.0.7

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2018-15762 2018-11-02 22h00 +00:00 Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
9
Critique
CVE-2018-11081 2018-10-05 21h00 +00:00 Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can now file search and find the UAA credentials for Operations Manager on the system disk..
8.8
Haute
CVE-2018-11045 2018-07-11 20h00 +00:00 Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.
5.9
Moyen