CVE-2018-15759: Pivotal Software Broker API
Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker operations.
Affected products
- Pivotal Software Broker API: before 3.0.2 (fixed in 3.0.2)
- Pivotal Software On Demand Services SDK: before 0.24.0 (fixed in 0.24.0)
Published 2018-11-19. Last modified 2026-06-17.