CRITICAL🇵🇱 Wersja polska

CVE-2018-15759

CVSS 9.1v3.0pub. 2018-11-19upd. 2024-11-21

Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker operations.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Pivotal Software Broker Api

    APP
    Pivotal Software
    < 3.0.2
  • Pivotal Software On Demand Services Sdk

    APP
    Pivotal Software
    < 0.24.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Spring Data Commons — podatność property bindera

CVE-2020-5415CRITICAL10.0PL ✓same vendor

Concourse GitLab Auth: identity spoofing przez podszywanie się pod użytkownika

CVE-2019-3793CRITICAL9.8PL ✓same vendor

Pivotal Apps Manager — przechwycenie danych uwierzytelniających przez niezaszyfrowane HTTP

CVE-2018-15761CRITICAL9.9PL ✓same vendor

Privilege escalation w Cloud Foundry UAA poprzez manipulację stroną zgody

CVE-2018-15762CRITICAL9.0PL ✓same vendor

Pivotal Operations Manager — privilege escalation przez nieprawidłowe zarządzanie uprawnieniami