vciy

CVEs we hold for Pivotal

Records whose assigning authority named Pivotal as the affected vendor. Newest identifiers first, capped at 200.

CVE-2020-5409Concourse Open Redirect in the /sky/login endpointPivotal Concourse
CVE-2020-5406PCF Autoscaling logs its database credentialsPivotal VMware Tanzu Application Service for VMs
CVE-2020-5404Authentication Leak On Redirect With Reactor Netty HttpClientPivotal Reactor Netty
CVE-2020-5403DoS Via Malformed URL with Reactor Netty HTTP ServerPivotal Reactor Netty
CVE-2019-3803Concourse includes token in CLI authentication callbackPivotal Concourse
CVE-2019-3793Invitations Service supports HTTP connectionsPivotal Apps Manager
CVE-2019-3792Concourse 5.0.0 SQL Injection vulnerabilityPivotal Concourse
CVE-2019-3790Ops Manager uaa client issues tokens after refresh token expirationPivotal Ops Manager
CVE-2019-3777Apps Manager unverified SSL certs in Cloud Controller proxyPivotal Application Service
CVE-2019-3776Reflected XSS in Pivotal Operations ManagerPivotal Ops Manager
CVE-2019-11292Pivotal Ops Manager logs query parameters in tomcat access filePivotal Ops Manager
CVE-2019-11291RabbitMQ XSS attack via federation and shovel endpointsPivotal Platform
CVE-2019-11288tcServer JMX Socket Listener Registry Rebinding Local Privilege EscalationPivotal tc Server 3.x Runtimes
CVE-2019-11287RabbitMQ Web Management Plugin DoS via heap overflowPivotal RabbitMQ
CVE-2019-11284Reactor Netty authentication leak in redirectsPivotal Reactor Netty
CVE-2019-11281RabbitMQ XSS attackPivotal RabbitMQ for PCF
CVE-2019-11280Privilege escalation through the invitations servicePivotal Application Service (PAS)
CVE-2019-11276Apps Manager sends tokens to Spring apps via HTTPPivotal Application Service (PAS)
CVE-2019-11275CSV Injection in usage report downloaded from Pivotal Application ManagerPivotal Apps Manager
CVE-2019-11273PKS Telemetry logs credentialsPivotal Container Service (PKS)
CVE-2018-15798Pivotal Concourse allows malicious redirect urls on loginPivotal Concourse
CVE-2018-15795CredHub Service Broker uses guessable client secretPivotal Cloud Foundry CredHub Service Broker
CVE-2018-15763PKS leaks IaaS Credentials to Application LogsPivotal Container Service
CVE-2018-15762Pivotal Operations Manager gives all users heightened privilegesPivotal Operations Manager
CVE-2018-15759On Demand Services SDK Timing Attack VulnerabilityPivotal On Demand Services SDK
CVE-2018-15758Privilege Escalation in spring-security-oauth2Pivotal Spring Security OAuth
CVE-2018-15756DoS Attack via Range RequestsPivotal Spring framework
CVE-2018-1280no title heldPivotal Greenplum Command Center
CVE-2018-1279RabbitMQ cluster compromise due to deterministically generated cookiePivotal RabbitMq for PCF
CVE-2018-1278no title heldPivotal Application Service
CVE-2018-1263no title heldPivotal Spring Integration Zip
CVE-2018-1261no title heldPivotal Spring Integration Zip
CVE-2018-1260no title heldPivotal Spring Security OAuth
CVE-2018-1259no title heldPivotal Spring Data Commons
CVE-2018-1258no title heldPivotal Spring Framework
CVE-2018-1257no title heldPivotal Spring Framework
CVE-2018-1256no title heldPivotal Spring Cloud SSO Connector
CVE-2018-1198no title heldPivotal Cloud Cache
CVE-2018-1190no title heldn/a Pivotal Cloud Foundry products: all versions prior to…
CVE-2018-11088no title heldPivotal Application Service
CVE-2018-11087TLS validation errorPivotal Spring AMQP
CVE-2018-11086no title heldPivotal Application Service
CVE-2018-11081Pivotal Operations Manager UAA config - temp Ram Diskpivotal-ops-manager
CVE-2018-11049RSA Identity Governance and Lifecycle Uncontrolled Search Path VulnerabilityPivotal Operations Manager
CVE-2018-11046no title heldPivotal Operations Manager
CVE-2018-11045no title heldPivotal Operations Manager
CVE-2018-11044no title heldPivotal Application Service
CVE-2018-11040no title heldPivotal Spring Framework
CVE-2018-11039no title heldPivotal Spring Framework
CVE-2017-8046no title heldPivotal Spring Data REST and Spring Boot
CVE-2017-4967no title heldn/a Pivotal RabbitMQ
CVE-2017-4966no title heldn/a Pivotal RabbitMQ
CVE-2017-4965no title heldn/a Pivotal RabbitMQ
CVE-2017-3203Pivotal/Spring Spring-flex's Action Message Format (AMF3) Java implementation is vulnerable to insecure deserializationPivotal/Spring Spring-flex
CVE-2016-9879no title heldn/a Pivotal Spring Security before 3.2.10, 4.1.x before…
CVE-2016-9878no title heldn/a Pivotal Spring Framework before 3.2.18, 4.2.x before…
CVE-2016-9877no title heldn/a Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before…
CVE-2016-8220no title heldPivotal Gemfire for PCF
CVE-2016-6656no title heldn/a Pivotal Greenplum 4.3.0.0 to 4.3.9.1 and older versions…
CVE-2016-5007no title heldPivotal Spring Framework
CVE-2016-4977no title heldPivotal Spring Security OAuth
CVE-2016-4435no title heldPivotal Cloud Foundry
CVE-2016-3084no title heldPivotal Cloud Foundry
CVE-2016-2165no title heldPivotal Cloud Foundry
CVE-2016-0781no title heldPivotal Cloud Foundry
CVE-2016-0780no title heldPivotal Cloud Foundry
CVE-2016-0761no title heldPivotal Cloud Foundry
CVE-2016-0715no title heldPivotal Cloud Foundry Elastic Runtime
CVE-2015-3191no title heldPivotal Cloud Foundry
CVE-2015-3190no title heldPivotal Cloud Foundry
CVE-2015-3189no title heldPivotal Cloud Foundry
CVE-2015-1834no title heldPivotal Cloud Foundry
CVE-2014-3527no title heldPivotal Spring Security
CVE-2014-0225no title heldPivotal Spring Framework
CVE-2014-0097no title heldPivotal Spring Security
CVE-2013-6430no title heldPivotal Spring MVC

76 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.