CVE-2018-15795
CVSS v3.0
8.1 (High)
CVSS v2.0
5.5 (Medium)
EPSS
0.06 % (25th)
Affected Products
1
Advisories
1
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Weaknesses
- CWE-338
- Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
- CVE Status
- PUBLISHED
- CNA
- Dell
- Published Date
-
2018-11-13 14:29:00
(5 years ago) - Updated Date
-
2019-10-09 23:35:54
(5 years ago)
Affected Products
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...