CVE-2018-11046: Input Validation
Pivotal Operations Manager, versions 2.1.x prior to 2.1.6 and version 2.0.14, includes NGINX packages that lacks security vulnerability patches. An attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities may be able to impact Operations Manager
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11046?
CVE-2018-11046 is a vulnerability in Pivotal Operations Manager versions 2.1.x prior to 2.1.6 and version 2.0.14 that includes unpatched NGINX packages.
How does CVE-2018-11046 affect Pivotal Operations Manager?
CVE-2018-11046 allows an attacker with access to the NGINX processes and knowledge of how to exploit the unpatched vulnerabilities to impact Operations Manager.
What is the severity of CVE-2018-11046?
CVE-2018-11046 has a severity value of 6.5, which is considered medium.
Which software versions are affected by CVE-2018-11046?
Pivotal Operations Manager versions 2.1.x prior to 2.1.6 and version 2.0.14 are affected by CVE-2018-11046.
How can I fix CVE-2018-11046?
To fix CVE-2018-11046, update Pivotal Operations Manager to version 2.1.6 or apply the necessary security patches.