Cloudfoundry Uaa Release
Vendor:
First CVE: Apr 24, 2017 · Active for 9 years
10
Total CVEs
More Total CVEs than 53% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 86% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloudfoundry Uaa Release over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2017
9 years ago
Most Recent CVE
Jul 11, 2019
2,574 days ago
CVE Severity & Scoring
Cloudfoundry Uaa Release10 CVEs
30%
60%
10%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low4 (40.0%)
High1 (10.0%)
None5 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11082CRITICAL Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious use | Oct 5, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-15761HIGH Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated use | Nov 19, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-15754HIGH Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers | Dec 13, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-1192HIGH In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x ver | Feb 1, 2018 | 8.8 | 27 | NO | NO |
CVE-2019-3787HIGH Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ charac | Jun 19, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-4963HIGH An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh rel | Jun 13, 2017 | 8.1 | 23 | NO | NO |
CVE-2018-1262HIGH Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validatio | May 15, 2018 | 7.2 | 22 | NO | NO |
CVE-2016-5016MEDIUM Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Run | Apr 24, 2017 | 5.9 | 21 | NO | NO |
CVE-2018-11041MEDIUM Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not v | Jun 25, 2018 | 6.1 | 20 | NO | NO |
CVE-2019-11268MEDIUM Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can e | Jul 11, 2019 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Cloudfoundry Uaa Release
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 58 | 1 | 7.2 | 1.3% | 0 | 0 |
| 57.1 | 1 | 7.2 | 1.3% | 0 | 0 |
| 57 | 1 | 7.2 | 1.3% | 0 | 0 |
| 53.3 | 1 | 8.8 | 1.0% | 0 | 0 |
| 52.7 | 1 | 8.8 | 1.0% | 0 | 0 |
| 45.7 | 1 | 8.8 | 1.0% | 0 | 0 |