Vulnerabilities > Cloudfoundry > UAA Release > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-09-26 CVE-2019-11279 Improper Privilege Management vulnerability in Cloudfoundry UAA Release
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes.
network
low complexity
cloudfoundry CWE-269
6.5
2019-04-25 CVE-2019-3801 Cleartext Transmission of Sensitive Information vulnerability in Cloudfoundry Cf-Deployment and Credhub
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building.
network
low complexity
cloudfoundry CWE-319
5.0
2019-04-25 CVE-2019-3788 Open Redirect vulnerability in Cloudfoundry UAA Release
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri.
5.8
2019-03-07 CVE-2019-3775 Improper Authentication vulnerability in Cloudfoundry UAA Release
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address.
network
low complexity
cloudfoundry CWE-287
4.0
2017-09-07 CVE-2016-0732 Improper Privilege Management vulnerability in multiple products
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
network
low complexity
cloudfoundry pivotal CWE-269
6.5