CVE-2018-15762

CRITICAL

Pivotal Operations Manager <2.0.24, <2.1.15, <2.2.7, <2.3.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2018-15762

Scores

CVSS v3 9.0
EPSS 0.0108
EPSS Percentile 60.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
pivotal_software/operations_manager 2.0.0 - 2.0.24
Published Nov 02, 2018
Tracked Since Feb 18, 2026