8.8

CVE-2016-0732

The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cloudfoundry ≫ Cf-release Version >= 208 <= 229
Cloudfoundry ≫ Uaa-release Version 2
Cloudfoundry ≫ Uaa-release Version 3
Cloudfoundry ≫ Uaa-release Version 4
Pivotal ≫ Elastic Runtime Version 1.6.0
Pivotal ≫ Elastic Runtime Version 1.6.1
Pivotal ≫ Elastic Runtime Version 1.6.2
Pivotal ≫ Elastic Runtime Version 1.6.3
Pivotal ≫ Elastic Runtime Version 1.6.4
Pivotal ≫ Elastic Runtime Version 1.6.5
Pivotal ≫ Elastic Runtime Version 1.6.6
Pivotal ≫ Elastic Runtime Version 1.6.7
Pivotal ≫ Elastic Runtime Version 1.6.8
Pivotal ≫ Elastic Runtime Version 1.6.9
Pivotal ≫ Elastic Runtime Version 1.6.10
Pivotal ≫ Elastic Runtime Version 1.6.11
Pivotal ≫ Elastic Runtime Version 1.6.12
Pivotal ≫ Elastic Runtime Version 1.6.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.629
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://pivotal.io/security/cve-2016-0732
Vendor Advisory
Mitigation