Pivotal Software's vulnerability footprint centers on a modestly represented but strategically important portfolio of platform-as-a-service and messaging infrastructure products, including Cloud Foundry, its UAA identity component, Elastic Runtime, RabbitMQ, and Operations Manager—components that often sit in the management and communication layers of containerized and cloud-native deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the access-control and data-handling demands of platform infrastructure. The exposure recurs across these products through weakness classes spanning information disclosure, cross-site scripting, log-injection flaws, and open-redirect conditions, patterns characteristic of web-facing and authentication-oriented services where input handling and trust boundaries carry outsized risk. Defenders should monitor this vendor's releases closely for components deployed in cloud environments and identity-management roles; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pivotal Software over time
Signals from CVEs in this vendor scope (173 CVEs).
173 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1273CRITICAL Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s | Apr 11, 2018 | 9.8 | 98 | YES | YES |
CVE-2017-8046CRITICAL Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5. | Jan 4, 2018 | 9.8 | 88 | NO | YES |
CVE-2016-4977HIGH When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri | May 25, 2017 | 8.8 | 81 | NO | YES |
CVE-2013-6429MEDIUM The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack | Jan 26, 2014 | 6.8 | 65 | NO | NO |
CVE-2019-3778MEDIUM Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to | Mar 7, 2019 | 6.5 | 41 | NO | YES |
CVE-2018-1260CRITICAL Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vuln | May 11, 2018 | 9.8 | 35 | NO | NO |
CVE-2019-11269MEDIUM Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an | Jun 12, 2019 | 5.4 | 34 | NO | YES |
CVE-2016-9877CRITICAL An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ | Dec 29, 2016 | 9.8 | 33 | NO | NO |
CVE-2019-3774CRITICAL Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | Jan 18, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3773CRITICAL Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data fr | Jan 18, 2019 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (173 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotal Software.
Media articles that mention a CVE ID that affects a product developed by Pivotal Software — matched by CVE ID, not by vendor name.