PT-2018-10266 · Nginx+1 · Nginx+1

Published

2018-06-25

·

Updated

2018-08-30

·

CVE-2018-11046

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Operations Manager versions 2.0.14 Pivotal Operations Manager versions 2.1.x prior to 2.1.6
Description The issue concerns unpatched security vulnerabilities in NGINX packages included in Pivotal Operations Manager. An attacker with access to the NGINX processes and knowledge of how to exploit these vulnerabilities may impact Operations Manager.
Recommendations For version 2.0.14, update to a version that includes the necessary security patches for NGINX. For versions 2.1.x prior to 2.1.6, update to version 2.1.6 or later to include the necessary security patches for NGINX.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11046

Affected Products

Nginx
Pivotal Operations Manager