Vulnerability Description
Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can now file search and find the UAA credentials for Operations Manager on the system disk..
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Operations Manager | >= 1.11.0, < 1.12.25 |
References
- https://pivotal.io/security/cve-2018-11081Vendor Advisory
- https://pivotal.io/security/cve-2018-11081Vendor Advisory
FAQ
What is CVE-2018-11081?
CVE-2018-11081 is a vulnerability with a CVSS score of 7.9 (HIGH). Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk,...
How severe is CVE-2018-11081?
CVE-2018-11081 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11081?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Operations Manager.