Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker operations.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NPivotal Software Broker Api
APPPivotal Software< 3.0.2Pivotal Software On Demand Services Sdk
APPPivotal Software< 0.24.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓same vendor
RCE w Spring Data Commons — podatność property bindera
CVE-2020-5415CRITICAL10.0PL ✓same vendor
Concourse GitLab Auth: identity spoofing przez podszywanie się pod użytkownika
CVE-2019-3793CRITICAL9.8PL ✓same vendor
Pivotal Apps Manager — przechwycenie danych uwierzytelniających przez niezaszyfrowane HTTP
CVE-2018-15761CRITICAL9.9PL ✓same vendor
Privilege escalation w Cloud Foundry UAA poprzez manipulację stroną zgody
CVE-2018-15762CRITICAL9.0PL ✓same vendor
Pivotal Operations Manager — privilege escalation przez nieprawidłowe zarządzanie uprawnieniami