Pivotal Software Operations Manager 2.1.7

CPE Details

Pivotal Software Operations Manager 2.1.7
2.1.7
2018-11-26
17h58 +00:00
2018-11-26
17h58 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:pivotal_software:operations_manager:2.1.7:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

operations_manager

Version

2.1.7

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-3776 2019-03-07 19h00 +00:00 Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince an Operations Manager user to interact with malicious content could execute arbitrary JavaScript in the user's browser.
7.2
Haute
CVE-2018-15762 2018-11-02 22h00 +00:00 Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
9
Critique
CVE-2018-11081 2018-10-05 21h00 +00:00 Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can now file search and find the UAA credentials for Operations Manager on the system disk..
8.8
Haute