Home / CVEs we hold for Pivotal CVEs we hold for Pivotal Records whose assigning authority named Pivotal as the affected vendor. Newest identifiers first, capped at 200.
CVE-2020-5409 Concourse Open Redirect in the /sky/login endpoint Pivotal Concourse CVE-2020-5406 PCF Autoscaling logs its database credentials Pivotal VMware Tanzu Application Service for VMs CVE-2020-5404 Authentication Leak On Redirect With Reactor Netty HttpClient Pivotal Reactor Netty CVE-2020-5403 DoS Via Malformed URL with Reactor Netty HTTP Server Pivotal Reactor Netty CVE-2019-3803 Concourse includes token in CLI authentication callback Pivotal Concourse CVE-2019-3793 Invitations Service supports HTTP connections Pivotal Apps Manager CVE-2019-3792 Concourse 5.0.0 SQL Injection vulnerability Pivotal Concourse CVE-2019-3790 Ops Manager uaa client issues tokens after refresh token expiration Pivotal Ops Manager CVE-2019-3777 Apps Manager unverified SSL certs in Cloud Controller proxy Pivotal Application Service CVE-2019-3776 Reflected XSS in Pivotal Operations Manager Pivotal Ops Manager CVE-2019-11292 Pivotal Ops Manager logs query parameters in tomcat access file Pivotal Ops Manager CVE-2019-11291 RabbitMQ XSS attack via federation and shovel endpoints Pivotal Platform CVE-2019-11288 tcServer JMX Socket Listener Registry Rebinding Local Privilege Escalation Pivotal tc Server 3.x Runtimes CVE-2019-11287 RabbitMQ Web Management Plugin DoS via heap overflow Pivotal RabbitMQ CVE-2019-11284 Reactor Netty authentication leak in redirects Pivotal Reactor Netty CVE-2019-11280 Privilege escalation through the invitations service Pivotal Application Service (PAS) CVE-2019-11276 Apps Manager sends tokens to Spring apps via HTTP Pivotal Application Service (PAS) CVE-2019-11275 CSV Injection in usage report downloaded from Pivotal Application Manager Pivotal Apps Manager CVE-2019-11273 PKS Telemetry logs credentials Pivotal Container Service (PKS) CVE-2018-15798 Pivotal Concourse allows malicious redirect urls on login Pivotal Concourse CVE-2018-15795 CredHub Service Broker uses guessable client secret Pivotal Cloud Foundry CredHub Service Broker CVE-2018-15763 PKS leaks IaaS Credentials to Application Logs Pivotal Container Service CVE-2018-15762 Pivotal Operations Manager gives all users heightened privileges Pivotal Operations Manager CVE-2018-15759 On Demand Services SDK Timing Attack Vulnerability Pivotal On Demand Services SDK CVE-2018-15758 Privilege Escalation in spring-security-oauth2 Pivotal Spring Security OAuth CVE-2018-1279 RabbitMQ cluster compromise due to deterministically generated cookie Pivotal RabbitMq for PCF CVE-2018-1190 no title held n/a Pivotal Cloud Foundry products: all versions prior to… CVE-2018-11081 Pivotal Operations Manager UAA config - temp Ram Disk pivotal-ops-manager CVE-2018-11049 RSA Identity Governance and Lifecycle Uncontrolled Search Path Vulnerability Pivotal Operations Manager CVE-2017-8046 no title held Pivotal Spring Data REST and Spring Boot CVE-2017-3203 Pivotal/Spring Spring-flex's Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization Pivotal/Spring Spring-flex CVE-2016-9879 no title held n/a Pivotal Spring Security before 3.2.10, 4.1.x before… CVE-2016-9878 no title held n/a Pivotal Spring Framework before 3.2.18, 4.2.x before… CVE-2016-9877 no title held n/a Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before… CVE-2016-6656 no title held n/a Pivotal Greenplum 4.3.0.0 to 4.3.9.1 and older versions… 76 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.