CVE-2018-11088: Pivotal Software Pivotal Application Service

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Pivotal Applications Manager in Pivotal Application Service, versions 2.0 prior to 2.0.21 and 2.1 prior to 2.1.13 and 2.2 prior to 2.2.5, contains a bug which may allow escalation of privileges. A space developer with access to the system org may be able to access an artifact which contains the CF admin credential, allowing them to escalate to an admin role.

Affected products

  • Pivotal Software Pivotal Application Service: from 2.0.0, before 2.0.21 (fixed in 2.0.21); from 2.1.0, before 2.1.13 (fixed in 2.1.13); from 2.2.0, before 2.2.5 (fixed in 2.2.5)

Published 2018-09-17. Last modified 2026-06-17.