CVE-2018-11045

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
11/07/2018
Last modified:
14/09/2018

Description

Pivotal Operations Manager, versions 2.1 prior to 2.1.6 and 2.0 prior to 2.0.15 and 1.12 prior to 1.12.22, contains a static Linux Random Number Generator (LRNG) seed file embedded in the appliance image. An attacker with knowledge of the exact version and IaaS of a running OpsManager could get the contents of the corresponding seed from the published image and therefore infer the initial state of the LRNG.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:* 1.12 (including) 1.12.22 (excluding)
cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:* 2.0 (excluding) 2.0.15 (excluding)
cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.6 (excluding)


References to Advisories, Solutions, and Tools