Pivotal Software Application Service vulnerabilities
4 known vulnerabilities affecting pivotal_software/application_service.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-11276MEDIUMCVSS 5.4≥ 2.3.0, < 2.3.16≥ 2.4.0, < 2.4.12+2 more2019-08-19
CVE-2019-11276 [MEDIUM] CWE-319 CVE-2019-11276: Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent requests via unsecured http. An adjacent unauthenticated user could eavesdrop on the network traffic
nvd
CVE-2019-11270HIGHCVSS 7.5≥ 2.3.0, < 2.3.15≥ 2.4.0, < 2.4.11+2 more2019-08-05
CVE-2019-11270 [HIGH] CWE-269 CVE-2019-11270: Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possess
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
nvd
CVE-2019-3793CRITICALCVSS 9.8≥ 665.0.0, < 665.0.28≥ 666.0.0, < 666.0.21+1 more2019-04-24
CVE-2019-3793 [CRITICAL] CWE-300 CVE-2019-3793: Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.
nvd
CVE-2019-3777CRITICALCVSS 9.8≥ 2.2.0, < 2.2.12≥ 2.3.0, < 2.3.7+1 more2019-03-07
CVE-2019-3777 [CRITICAL] CWE-295 CVE-2019-3777: Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x pr
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's DNS record could intercept access tokens sent to the Cloud Controller, giv
nvd