Pivotal Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Pivotal products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
2
In CISA KEV
1
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Pivotal KEVs Added by Year
Loading...
2 Pivotal KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-1273
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability... |
Spring Framework | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-8046
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and... |
Pivotal Spring Data REST and Spring Boot | High | Not in CISA | 04 Jan 2018 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology