Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pivotal Software

First CVE: Jan 26, 2014Active for: 12 yearsTotal CVEs: 176
57.9
VTI Score
TOP TARGET

Pivotal Software's vulnerability footprint centers on a modestly represented but strategically important portfolio of platform-as-a-service and messaging infrastructure products, including Cloud Foundry, its UAA identity component, Elastic Runtime, RabbitMQ, and Operations Manager—components that often sit in the management and communication layers of containerized and cloud-native deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the access-control and data-handling demands of platform infrastructure. The exposure recurs across these products through weakness classes spanning information disclosure, cross-site scripting, log-injection flaws, and open-redirect conditions, patterns characteristic of web-facing and authentication-oriented services where input handling and trust boundaries carry outsized risk. Defenders should monitor this vendor's releases closely for components deployed in cloud environments and identity-management roles; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
173
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Pivotal Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2014
12 years ago
Most Recent CVE
Jan 12, 2024
925 days ago

Products(49 total)

Top CVEs

Signals from CVEs in this vendor scope (173 CVEs).

173 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1273CRITICAL
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s
Apr 11, 20189.898YESYES
CVE-2017-8046CRITICAL
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.
Jan 4, 20189.888NOYES
CVE-2016-4977HIGH
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri
May 25, 20178.881NOYES
CVE-2013-6429MEDIUM
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack
Jan 26, 20146.865NONO
CVE-2019-3778MEDIUM
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to
Mar 7, 20196.541NOYES
CVE-2018-1260CRITICAL
Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vuln
May 11, 20189.835NONO
CVE-2019-11269MEDIUM
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an
Jun 12, 20195.434NOYES
CVE-2016-9877CRITICAL
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ
Dec 29, 20169.833NONO
CVE-2019-3774CRITICAL
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.
Jan 18, 20199.832NONO
CVE-2019-3773CRITICAL
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data fr
Jan 18, 20199.832NONO
View all 173 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products173 CVEs
35%
47%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (4.0%)
Network157 (90.8%)
Unknown7 (4.0%)
Physical0 (0.0%)
Adjacent Network2 (1.2%)
Attack Complexity
Low145 (83.8%)
High21 (12.1%)
Unknown7 (4.0%)
User Interaction
None133 (76.9%)
Unknown7 (4.0%)
Required33 (19.1%)
Privileges Required
Low52 (30.1%)
High9 (5.2%)
None105 (60.7%)
Unknown7 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (173 CVEs).

CISA KEV
1 CVE
0.6% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
1.7% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pivotal Software.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pivotal Software — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pivotal Software's Products

View all 6 CNAs →

Top CWEs