Pivotal Software Login-server

CPE Details

Pivotal Software Login-server
-
2017-06-07
15h38 +00:00
2021-08-06
13h13 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:pivotal_software:login-server:-:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

login-server

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-0781 2017-05-25 15h00 +00:00 The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
6.1
Medium
CVE-2016-3084 2017-05-25 15h00 +00:00 The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
8.1
High