Known Vulnerabilities for Cloud Foundry by Pivotal Software
Listed below are 10 of the newest known vulnerabilities associated with "Cloud Foundry" by "Pivotal Software".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-4960 | An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA B... | 7.5 - HIGH | 2017-03-10 | 2021-08-06 |
| CVE-2016-6659 | Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh relea... | 8.1 - HIGH | 2016-12-23 | 2021-08-06 |
| CVE-2016-6651 | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.... | 8.8 - HIGH | 2016-09-30 | 2021-08-06 |
| CVE-2016-6637 | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7,... | 9.6 - CRITICAL | 2016-09-30 | 2021-08-06 |
| CVE-2016-6636 | The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5,... | 5.3 - MEDIUM | 2016-09-30 | 2021-08-06 |
| CVE-2016-5016 | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 a... | 5.9 - MEDIUM | 2017-04-24 | 2019-02-26 |
| CVE-2016-5006 | The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to ob... | 9.8 - CRITICAL | 2017-05-02 | 2017-05-11 |
| CVE-2016-4468 | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x ... | 8.8 - HIGH | 2017-04-11 | 2023-11-07 |
| CVE-2016-3084 | The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all ... | 8.1 - HIGH | 2017-05-25 | 2021-08-06 |
| CVE-2016-0781 | The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to... | 6.1 - MEDIUM | 2017-05-25 | 2021-08-06 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Cloud Foundry | 242.0 | All | All | All |
| Application | Pivotal Software | Cloud Foundry | 241 | All | All | All |