CVE-2018-15762: Pivotal Software Operations Manager
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.
Affected products
- Pivotal Software Operations Manager: from 2.0.0, before 2.0.24 (fixed in 2.0.24); from 2.1.0, before 2.1.15 (fixed in 2.1.15); from 2.2.0, before 2.2.7 (fixed in 2.2.7); from 2.3.0, before 2.3.1 (fixed in 2.3.1)
Published 2018-11-02. Last modified 2026-06-17.