PT-2018-10266 · Nginx+1 · Nginx+1
Published
2018-06-25
·
Updated
2018-08-30
·
CVE-2018-11046
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal Operations Manager versions 2.0.14
Pivotal Operations Manager versions 2.1.x prior to 2.1.6
Description
The issue concerns unpatched security vulnerabilities in NGINX packages included in Pivotal Operations Manager. An attacker with access to the NGINX processes and knowledge of how to exploit these vulnerabilities may impact Operations Manager.
Recommendations
For version 2.0.14, update to a version that includes the necessary security patches for NGINX.
For versions 2.1.x prior to 2.1.6, update to version 2.1.6 or later to include the necessary security patches for NGINX.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nginx
Pivotal Operations Manager