Known Vulnerabilities for Cloud Foundry by Pivotal Software
Listed below are 10 of the newest known vulnerabilities associated with "Cloud Foundry" by "Pivotal Software".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-22734 json | Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-pr... | Not Provided | 2026-04-17 | 2026-04-17 |
| CVE-2017-4960 json | An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA B... | 7.5 - HIGH | 2017-03-10 | 2021-08-06 |
| CVE-2016-6659 json | Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh relea... | 8.1 - HIGH | 2016-12-23 | 2021-08-06 |
| CVE-2016-6651 json | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.... | 8.8 - HIGH | 2016-09-30 | 2021-08-06 |
| CVE-2016-6637 json | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7,... | 9.6 - CRITICAL | 2016-09-30 | 2021-08-06 |
| CVE-2016-6636 json | The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5,... | 5.3 - MEDIUM | 2016-09-30 | 2021-08-06 |
| CVE-2016-5016 json | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 a... | 5.9 - MEDIUM | 2017-04-24 | 2019-02-26 |
| CVE-2016-5006 json | The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to ob... | 9.8 - CRITICAL | 2017-05-02 | 2017-05-11 |
| CVE-2016-4468 json | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x ... | 8.8 - HIGH | 2017-04-11 | 2023-11-07 |
| CVE-2016-3084 json | The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all ... | 8.1 - HIGH | 2017-05-25 | 2021-08-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Cloud Foundry | 242.0 | |||
| Application | Pivotal Software | Cloud Foundry | 241 |