VYPR
Unrated severityNVD Advisory· Published Nov 2, 2018· Updated Sep 16, 2024

Pivotal Operations Manager gives all users heightened privileges

CVE-2018-15762

Description

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.

Affected products

2
  • Cloudfoundry/Operations Managerllm-fuzzy2 versions
    >= 2.0.0, < 2.0.24; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.7; >= 2.3.0, < 2.3.1+ 1 more
    • (no CPE)range: >= 2.0.0, < 2.0.24; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.7; >= 2.3.0, < 2.3.1
    • (no CPE)range: 2.0.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.