Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
174 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.2% | — | Pivotal Software Pivotal Application Service | 11/5/2018 | 17/6/2026 | Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation… | |
| Modificada | Crítica (9.8) | 11% | 💥 PoC | Pivotal Software Spring Security Oauth | 11/5/2018 | 17/6/2026 | Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker can craft an authorization request to the authorization endpoint that can lead to remote code… | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestXmlbeam | 11/5/2018 | 26/6/2026 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference… | |
| Modificada | Alta (8.8) | 2.5% | — | Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+38 | 11/5/2018 | 25/8/2026 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted. | |
| Analizada | Alta (7.5) | 1.9% | — | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data Rest | 18/4/2018 | 26/6/2026 | Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property… | |
| Modificada | Alta (7.5) | 1.1% | — | Pivotal Software Gemfire | 18/4/2018 | 17/6/2026 | Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application inadvertently exposed WAN replication credentials at a public route. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestApache Ignite+1 | 11/4/2018 | 26/8/2026 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data… | |
| Modificada | Crítica (9.6) | 0.87% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime | 29/3/2018 | 17/6/2026 | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a… | |
| Modificada | Crítica (10) | 1.4% | — | Vmware Pivotal Software Mysql | 29/3/2018 | 17/6/2026 | MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM. | |
| Modificada | Alta (8.8) | 0.97% | — | Pivotal Software Bosh CLI | 27/3/2018 | 17/6/2026 | Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH. | |
| Modificada | Alta (8.8) | 0.67% | — | Pivotal Software Spring Batch Admin | 21/3/2018 | 17/6/2026 | Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This issue has not been patched because Spring Batch Admin has reached end of life. | |
| Modificada | Media (6.1) | 0.71% | — | Pivotal Software Spring Batch Admin | 21/3/2018 | 17/6/2026 | Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has… | |
| Modificada | Alta (8.5) | 0.64% | — | Pivotal Software Windows Stemcells | 19/3/2018 | 17/6/2026 | In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials. | |
| Modificada | Media (6.5) | 1.3% | — | Pivotal Software Pivotal Application Service | 16/3/2018 | 17/6/2026 | Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote file read in its container via specially-crafted links. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pivotal Software Gemfire FOR Pivotal Cloud Foundry | 16/3/2018 | 17/6/2026 | The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker. | |
| Modificada | Alta (7.5) | 1.2% | — | Pivotal Software Concourse | 13/3/2018 | 17/6/2026 | Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project has been registered by an unknown… | |
| Modificada | Alta (8.8) | 1.0% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releasePivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry Cf-deployment | 1/2/2018 | 17/6/2026 | In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the… | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry Cf-releasePivotal UAAPivotal UAA Bosh | 4/1/2018 | 17/6/2026 | An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID… | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Vmware Spring BootPivotal Software Spring Data RestVmware Spring Data Rest | 4/1/2018 | 26/6/2026 | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. | |
| Modificada | Crítica (9.8) | 3.6% | — | Pivotal Software Spring Advanced Message Queuing Protocol | 27/11/2017 | 17/6/2026 | In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack. | |
| Modificada | Media (6.1) | 0.88% | — | Vmware Single Sign-on FOR Pivotal Cloud Foundry | 27/11/2017 | 17/6/2026 | In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks. | |
| Modificada | Alta (8.8) | 0.95% | — | Pivotal Software Credhub-release | 27/11/2017 | 17/6/2026 | In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential… | |
| Modificada | Alta (8.1) | 2.6% | — | Pivotal Software Spring-ldapDebian Linux | 27/11/2017 | 17/6/2026 | In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication… | |
| Modificada | Alta (7.5) | 1.4% | — | Pivotal Software Cf-deployment | 27/11/2017 | 17/6/2026 | In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locations. | |
| Modificada | Alta (7.8) | 0.73% | — | Pivotal Software Grootfs | 13/11/2017 | 17/6/2026 | Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide an image layer that GrootFS would consider to be the Ubuntu base layer. |