PT-2019-16720 · Pivotal · Pivotal Ops Manager

Published

2019-06-06

·

Updated

2019-10-09

·

CVE-2019-3790

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Ops Manager versions prior to 2.2.23 Pivotal Ops Manager versions prior to 2.3.16 Pivotal Ops Manager versions prior to 2.4.11 Pivotal Ops Manager versions prior to 2.5.3
Description The issue concerns configuration that circumvents refresh token expiration, allowing a remote authenticated user to gain access to a browser session that was supposed to have expired and access Ops Manager resources.
Recommendations For versions prior to 2.2.23, update to version 2.2.23 or later. For versions prior to 2.3.16, update to version 2.3.16 or later. For versions prior to 2.4.11, update to version 2.4.11 or later. For versions prior to 2.5.3, update to version 2.5.3 or later.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3790

Affected Products

Pivotal Ops Manager