6.1
CVE-2016-0781
- EPSS 0.66%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 2
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 3
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 4
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 5
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 6
Cloudfoundry ≫ Cloud Foundry Uaa Bosh Version 7
Pivotal Software ≫ Cloud Foundry Version 208
Pivotal Software ≫ Cloud Foundry Version 209
Pivotal Software ≫ Cloud Foundry Version 210
Pivotal Software ≫ Cloud Foundry Version 211
Pivotal Software ≫ Cloud Foundry Version 212
Pivotal Software ≫ Cloud Foundry Version 213
Pivotal Software ≫ Cloud Foundry Version 214
Pivotal Software ≫ Cloud Foundry Version 215
Pivotal Software ≫ Cloud Foundry Version 216
Pivotal Software ≫ Cloud Foundry Version 217
Pivotal Software ≫ Cloud Foundry Version 218
Pivotal Software ≫ Cloud Foundry Version 219
Pivotal Software ≫ Cloud Foundry Version 220
Pivotal Software ≫ Cloud Foundry Version 221
Pivotal Software ≫ Cloud Foundry Version 222
Pivotal Software ≫ Cloud Foundry Version 223
Pivotal Software ≫ Cloud Foundry Version 224
Pivotal Software ≫ Cloud Foundry Version 225
Pivotal Software ≫ Cloud Foundry Version 226
Pivotal Software ≫ Cloud Foundry Version 227
Pivotal Software ≫ Cloud Foundry Version 228
Pivotal Software ≫ Cloud Foundry Version 229
Pivotal Software ≫ Cloud Foundry Version 230
Pivotal Software ≫ Cloud Foundry Version 231
Pivotal Software ≫ Cloud Foundry Version 241
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.0
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.1
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.2
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.3
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.4
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.5
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.6
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.7
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.8
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.9
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.10
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.11
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.12
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.13
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.14
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.15
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.16
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.17
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.18
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version 1.6.19
Pivotal Software ≫ Cloud Foundry Uaa Version <= 2.7.4.1
Pivotal Software ≫ Cloud Foundry Uaa Version 3.0.0
Pivotal Software ≫ Cloud Foundry Uaa Version 3.0.1
Pivotal Software ≫ Cloud Foundry Uaa Version 3.1.0
Pivotal Software ≫ Cloud Foundry Uaa Version 3.2.0
Pivotal Software ≫ Login-server Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.465 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://pivotal.io/security/cve-2016-0781