Vulnerabilities > CVE-2016-3085 - 7PK - Security Features vulnerability in Apache Cloudstack

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
HIGH
Availability impact
NONE
network
high complexity
apache
CWE-254

Summary

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.

Common Weakness Enumeration (CWE)