CVE-2018-11081: Pivotal Operations Manager UAA config - temp Ram Disk
Pivotal Operations Manager, versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2, fails to write the Operations Manager UAA config onto the temp RAM disk, thus exposing the configs directly onto disk. A remote user that has gained access to the Operations Manager VM, can now file search and find the UAA credentials for Operations Manager on the system disk..
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11081?
CVE-2018-11081 is a vulnerability in Pivotal Operations Manager versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2 that exposes the Operations Manager UAA config directly onto disk.
What is the severity of CVE-2018-11081?
CVE-2018-11081 has a severity rating of 8.8 (high).
How does CVE-2018-11081 affect Pivotal Operations Manager?
CVE-2018-11081 affects Pivotal Operations Manager versions 2.2.x prior to 2.2.1, 2.1.x prior to 2.1.11, 2.0.x prior to 2.0.16, and 1.11.x prior to 2 by failing to write the Operations Manager UAA config onto the temp RAM disk, exposing the configs directly onto disk.
Is there a fix for CVE-2018-11081?
Yes, updating to Pivotal Operations Manager versions 2.2.1, 2.1.11, 2.0.16, or later resolves CVE-2018-11081.
Where can I find more information about CVE-2018-11081?
You can find more information about CVE-2018-11081 at the following link: [https://pivotal.io/security/cve-2018-11081](https://pivotal.io/security/cve-2018-11081)