VYPR
Critical severity9.0NVD Advisory· Published Nov 2, 2018· Updated Jun 17, 2026

CVE-2018-15762

CVE-2018-15762

Description

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.

Affected products

3
  • cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*range: >=2.0.0,<2.0.24
    • (no CPE)
    • (no CPE)range: 2.0.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.