CVE-2018-15762
CRITICALPivotal Operations Manager <2.0.24, <2.1.15, <2.2.7, <2.3.1 - Privilege Escalation
Title source: llmDescription
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2018-15762
Scores
CVSS v3
9.0
EPSS
0.0108
EPSS Percentile
60.8%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (1)
pivotal_software/operations_manager
2.0.0 - 2.0.24
Published
Nov 02, 2018
Tracked Since
Feb 18, 2026