CVE-2018-11046: Pivotal Software Operations Manager

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities may be able to impact Operations Manager

Affected products

  • Pivotal Software Operations Manager: from 2.1.0, before 2.1.6 (fixed in 2.1.6); version 2.0.14 only

Published 2018-06-25. Last modified 2026-06-17.