Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pivotal Software (VMware Tanzu)

First CVE: Jan 26, 2014Active for: 12 yearsTotal CVEs: 176
44.5
VTI Score
High

Pivotal Software, now part of the VMware Tanzu portfolio, develops a focused set of cloud-native and containerization platforms, notably Cloud Foundry deployment and runtime environments, along with complementary components such as Reactor Netty and Harbor Registry, that serve as central infrastructure for enterprise application platforms. The vulnerability exposure clusters around authentication and data-handling weaknesses—including insufficiently protected credentials, sensitive information leakage into logs, SQL injection, and improper privilege management—which reflect the integration demands and multi-tenant isolation requirements of platform-as-a-service systems. A meaningful share of the vendor's disclosed vulnerabilities reach serious severity levels, consistent with the blast radius of flaws in foundational cloud infrastructure that can affect numerous downstream workloads. Defenders should prioritize updates to Cloud Foundry and its backing services as part of their platform-layer patching discipline, since remediation often gates application deployments; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
173
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.6%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pivotal Software (VMware Tanzu) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2014
12 years ago
Most Recent CVE
Jan 12, 2024
924 days ago

Self-Reporting Analysis

Of all the CVEs published by Pivotal Software (VMware Tanzu) as a CNA, 8.6% affect products that Pivotal Software (VMware Tanzu) develops as a vendor.

91.4%
Self-reported: 5 (8.6%)
Third-party: 53 (91.4%)

Of all the CVEs published that affect products developed by Pivotal Software (VMware Tanzu), 15.6% are self-published by Pivotal Software (VMware Tanzu) as a CNA.

15.6%
84.4%
Self-published: 5 (15.6%)
Other CNAs: 27 (84.4%)

Products(38 total)

Top CVEs

Signals from CVEs in this vendor scope (173 CVEs).

173 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1273CRITICAL
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s
Apr 11, 20189.898YESYES
CVE-2017-8046CRITICAL
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.
Jan 4, 20189.888NOYES
CVE-2016-4977HIGH
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri
May 25, 20178.881NOYES
CVE-2013-6429MEDIUM
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack
Jan 26, 20146.865NONO
CVE-2019-3778MEDIUM
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to
Mar 7, 20196.541NOYES
CVE-2018-1260CRITICAL
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vuln
May 11, 20189.835NONO
CVE-2019-11269MEDIUM
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an
Jun 12, 20195.434NOYES
CVE-2016-9877CRITICAL
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ
Dec 29, 20169.833NONO
CVE-2019-3774CRITICAL
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Jan 18, 20199.832NONO
CVE-2019-3773CRITICAL
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data fr
Jan 18, 20199.832NONO
View all 173 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products173 CVEs
35%
47%
16%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (4.0%)
Network157 (90.8%)
Unknown7 (4.0%)
Physical0 (0.0%)
Adjacent Network2 (1.2%)
Attack Complexity
Low145 (83.8%)
High21 (12.1%)
Unknown7 (4.0%)
User Interaction
None133 (76.9%)
Unknown7 (4.0%)
Required33 (19.1%)
Privileges Required
Low52 (30.1%)
High9 (5.2%)
None105 (60.7%)
Unknown7 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (173 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
1.7% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.7% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotal Software (VMware Tanzu).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pivotal Software (VMware Tanzu) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pivotal Software (VMware Tanzu)'s Products

View all 6 CNAs →

Top CWEs