CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
78.3%
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers’ installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
Vendor | Product | Version | CPE |
---|---|---|---|
pivotal_software | operations_manager | * | cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.0 | cpe:2.3:a:pivotal_software:operations_manager:1.6.0:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.1 | cpe:2.3:a:pivotal_software:operations_manager:1.6.1:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.2 | cpe:2.3:a:pivotal_software:operations_manager:1.6.2:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.3 | cpe:2.3:a:pivotal_software:operations_manager:1.6.3:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.4 | cpe:2.3:a:pivotal_software:operations_manager:1.6.4:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.5 | cpe:2.3:a:pivotal_software:operations_manager:1.6.5:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.6 | cpe:2.3:a:pivotal_software:operations_manager:1.6.6:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.7 | cpe:2.3:a:pivotal_software:operations_manager:1.6.7:*:*:*:*:*:*:* |
pivotal_software | operations_manager | 1.6.8 | cpe:2.3:a:pivotal_software:operations_manager:1.6.8:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
78.3%