CVE-2018-11081 Information
Feb 14, 2021
cve
Description
Pivotal Operations Manager versions 2.2.x prior to 2.2.1 2.1.x prior to 2.1.11 2.0.x prior to 2.0.16 and 1.11.x prior to 2 fails to write the Operations Manager UAA config onto the temp RAM disk thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM can now file search and find the UAA credentials for Operations Manager on the system disk..
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://pivotal.io/security/cve-2018-11081
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: