Lucene search

K
cveDellCVE-2018-1278
HistoryMay 11, 2018 - 8:29 p.m.

CVE-2018-1278

2018-05-1120:29:00
CWE-863
dell
web.nvd.nist.gov
31
cve
2018
1278
apps manager
pivotal application service
authorization
vulnerability
org
information security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

47.6%

Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.

Affected configurations

Nvd
Node
pivotal_softwarepivotal_application_serviceRange1.12.01.12.22
OR
pivotal_softwarepivotal_application_serviceRange2.0.02.0.13
OR
pivotal_softwarepivotal_application_serviceRange2.1.02.1.4
VendorProductVersionCPE
pivotal_softwarepivotal_application_service*cpe:2.3:a:pivotal_software:pivotal_application_service:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Pivotal Application Service",
    "vendor": "Pivotal",
    "versions": [
      {
        "status": "affected",
        "version": "1.12.x prior to 1.12.22 and 2.0.x prior to 2.0.13 and 2.1.x prior to 2.1.4"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

47.6%

Related for CVE-2018-1278