CVE-2019-3790: Pivotal Software Operations Manager

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.

Affected products

  • Pivotal Software Operations Manager: from 2.2.0, before 2.2.23 (fixed in 2.2.23); from 2.3.0, before 2.3.16 (fixed in 2.3.16); from 2.4.0, before 2.4.11 (fixed in 2.4.11); from 2.5.0, before 2.5.3 (fixed in 2.5.3)

Published 2019-06-06. Last modified 2026-06-17.