Pivotal Software Cloud Foundry UAA-release 12

CPE Details

Pivotal Software Cloud Foundry UAA-release 12
12
2018-06-26
16h22 +00:00
2018-06-26
16h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:12:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

cloud_foundry_uaa-release

Version

12

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-11268 2019-07-11 18h11 +00:00 Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.
4.3
Medium
CVE-2019-3787 2019-06-19 22h28 +00:00 Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account.
8.8
High
CVE-2016-5016 2017-04-24 17h00 +00:00 Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
5.9
Medium