CVE-2018-15762
Pivotal Operations Manager gives all users heightened privileges
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Pivotal Operations Manager, en versiones 2.0.x anteriores a la 2.0.24, versiones 2.1.x anteriores a la 2.1.15, versiones 2.2.x anteriores a la 2.2.7 y versiones 2.3.x anteriores a la 2.3.1, otorga a todos los usuarios un alcance que permite el escalado de privilegios. Un usuario remoto malicioso que se haya autenticado podrĂa crear un nuevo cliente con privilegios de administrador para Opsman.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-23 CVE Reserved
- 2018-11-02 CVE Published
- 2024-08-13 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pivotal.io/security/cve-2018-15762 | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Operations Manager Search vendor "Pivotal Software" for product "Operations Manager" | >= 2.0.0 < 2.0.24 Search vendor "Pivotal Software" for product "Operations Manager" and version " >= 2.0.0 < 2.0.24" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Operations Manager Search vendor "Pivotal Software" for product "Operations Manager" | >= 2.1.0 < 2.1.15 Search vendor "Pivotal Software" for product "Operations Manager" and version " >= 2.1.0 < 2.1.15" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Operations Manager Search vendor "Pivotal Software" for product "Operations Manager" | >= 2.2.0 < 2.2.7 Search vendor "Pivotal Software" for product "Operations Manager" and version " >= 2.2.0 < 2.2.7" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Operations Manager Search vendor "Pivotal Software" for product "Operations Manager" | >= 2.3.0 < 2.3.1 Search vendor "Pivotal Software" for product "Operations Manager" and version " >= 2.3.0 < 2.3.1" | - |
Affected
|