PT-2018-10265 · Pivotal · Pivotal Operations Manager

Published

2018-07-11

·

Updated

2018-09-14

·

CVE-2018-11045

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Operations Manager versions 2.1 prior to 2.1.6 Pivotal Operations Manager versions 2.0 prior to 2.0.15 Pivotal Operations Manager versions 1.12 prior to 1.12.22
Description The issue concerns a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could infer the initial state of the LRNG by obtaining the contents of the corresponding seed from the published image.
Recommendations For versions 2.1 prior to 2.1.6, update to version 2.1.6 or later. For versions 2.0 prior to 2.0.15, update to version 2.0.15 or later. For versions 1.12 prior to 1.12.22, update to version 1.12.22 or later.

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11045

Affected Products

Pivotal Operations Manager