Pivotal Software, now part of the VMware Tanzu portfolio, develops a focused set of cloud-native and containerization platforms, notably Cloud Foundry deployment and runtime environments, along with complementary components such as Reactor Netty and Harbor Registry, that serve as central infrastructure for enterprise application platforms. The vulnerability exposure clusters around authentication and data-handling weaknesses—including insufficiently protected credentials, sensitive information leakage into logs, SQL injection, and improper privilege management—which reflect the integration demands and multi-tenant isolation requirements of platform-as-a-service systems. A meaningful share of the vendor's disclosed vulnerabilities reach serious severity levels, consistent with the blast radius of flaws in foundational cloud infrastructure that can affect numerous downstream workloads. Defenders should prioritize updates to Cloud Foundry and its backing services as part of their platform-layer patching discipline, since remediation often gates application deployments; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pivotal Software (VMware Tanzu) over time
Of all the CVEs published by Pivotal Software (VMware Tanzu) as a CNA, 8.6% affect products that Pivotal Software (VMware Tanzu) develops as a vendor.
Of all the CVEs published that affect products developed by Pivotal Software (VMware Tanzu), 15.6% are self-published by Pivotal Software (VMware Tanzu) as a CNA.
Signals from CVEs in this vendor scope (173 CVEs).
173 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1273CRITICAL Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s | Apr 11, 2018 | 9.8 | 98 | YES | YES |
CVE-2017-8046CRITICAL Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5. | Jan 4, 2018 | 9.8 | 88 | NO | YES |
CVE-2016-4977HIGH When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri | May 25, 2017 | 8.8 | 81 | NO | YES |
CVE-2013-6429MEDIUM The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack | Jan 26, 2014 | 6.8 | 65 | NO | NO |
CVE-2019-3778MEDIUM Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to | Mar 7, 2019 | 6.5 | 41 | NO | YES |
CVE-2018-1260CRITICAL Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vuln | May 11, 2018 | 9.8 | 35 | NO | NO |
CVE-2019-11269MEDIUM Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an | Jun 12, 2019 | 5.4 | 34 | NO | YES |
CVE-2016-9877CRITICAL An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ | Dec 29, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-3774CRITICAL Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | Jan 18, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3773CRITICAL Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data fr | Jan 18, 2019 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (173 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotal Software (VMware Tanzu).
Media articles that mention a CVE ID that affects a product developed by Pivotal Software (VMware Tanzu) — matched by CVE ID, not by vendor name.