Vulnerabilities > Pivotal Software > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-25 CVE-2016-3084 Permissions, Privileges, and Access Controls vulnerability in multiple products
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time.
network
high complexity
pivotal-software cloudfoundry CWE-264
8.1
2017-05-25 CVE-2016-0780 Resource Management Errors vulnerability in multiple products
It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases.
network
low complexity
pivotal-software cloudfoundry CWE-399
7.5
2017-05-25 CVE-2015-3191 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the change_email form in UAA is vulnerable to a CSRF attack.
network
low complexity
pivotal-software cloudfoundry CWE-352
8.8
2017-05-25 CVE-2014-0225 XXE vulnerability in multiple products
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration.
network
low complexity
pivotal-software vmware CWE-611
8.8
2017-04-11 CVE-2016-4468 SQL Injection vulnerability in multiple products
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
pivotal-software cloudfoundry CWE-89
8.8
2017-03-10 CVE-2017-4960 An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26.
network
low complexity
pivotal-software cloudfoundry
7.5
2016-12-29 CVE-2016-9878 Path Traversal vulnerability in multiple products
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5.
network
low complexity
pivotal-software vmware CWE-22
7.5
2016-12-23 CVE-2016-6659 Improper Authentication vulnerability in multiple products
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
network
high complexity
pivotal-software cloudfoundry CWE-287
8.1
2016-12-16 CVE-2016-6657 Open Redirect vulnerability in Pivotal Software products
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components.
network
low complexity
pivotal-software CWE-601
7.4
2016-12-16 CVE-2016-6656 Command Injection vulnerability in Pivotal Software Greenplum
An issue was discovered in Pivotal Greenplum before 4.3.10.0.
network
low complexity
pivotal-software CWE-77
7.2