Vulnerabilities > Pivotal Software > Cloud Foundry UAA > 2.0.2

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-11282 Injection vulnerability in multiple products
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack.
network
low complexity
cloudfoundry pivotal-software CWE-74
4.0
2019-08-05 CVE-2019-11270 7PK - Security Features vulnerability in Pivotal Software products
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
network
low complexity
pivotal-software CWE-254
5.0
2019-07-18 CVE-2019-3794 Improper Restriction of Rendered UI Layers or Frames vulnerability in Pivotal Software Cloud Foundry UAA
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints.
4.3
2018-11-19 CVE-2018-15761 Unspecified vulnerability in Pivotal Software Cloud Foundry UAA and Cloudfoundry UAA Release
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation.
network
low complexity
pivotal-software
6.5
2017-10-24 CVE-2015-5173 Information Exposure vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
6.8
2017-10-24 CVE-2015-5172 Weak Password Recovery Mechanism for Forgotten Password vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
network
low complexity
cloudfoundry pivotal-software CWE-640
7.5
2017-10-24 CVE-2015-5171 Insufficient Session Expiration vulnerability in multiple products
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
network
low complexity
cloudfoundry pivotal-software CWE-613
7.5
2017-10-24 CVE-2015-5170 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
6.8
2017-06-13 CVE-2017-4994 Improper Input Validation vulnerability in multiple products
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior to v24.11, 30.x versions prior to 30.4, and other versions prior to v40.
network
low complexity
cloudfoundry pivotal-software CWE-20
5.0
2017-06-13 CVE-2017-4992 Improper Privilege Management vulnerability in multiple products
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior to v24.10, 30.x versions prior to 30.3, and other versions prior to v37.
network
low complexity
pivotal-software cloudfoundry CWE-269
7.5