Critical severity9.0NVD Advisory· Published Nov 2, 2018· Updated Jun 17, 2026
CVE-2018-15762
CVE-2018-15762
Description
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Affected products
3cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*range: >=2.0.0,<2.0.24
- (no CPE)
- (no CPE)range: 2.0.x
Patches
Vulnerability mechanics
References
1- pivotal.io/security/cve-2018-15762nvdVendor Advisory
News mentions
0No linked articles in our index yet.