Vulnerability Description
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Operations Manager | >= 2.0.0, < 2.0.24 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/cve-2018-15762Vendor Advisory
- https://pivotal.io/security/cve-2018-15762Vendor Advisory
FAQ
What is CVE-2018-15762?
CVE-2018-15762 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for ...
How severe is CVE-2018-15762?
CVE-2018-15762 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-15762?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Operations Manager.