Vulnerabilities > CVE-2018-15761 - Unspecified vulnerability in Pivotal Software Cloud Foundry UAA and Cloudfoundry UAA Release

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pivotal-software

Summary

Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.

Vulnerable Configurations

Part Description Count
Application
Pivotal_Software
370