5.9

CVE-2016-5016

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal Software ≫ Cloud Foundry Version <= 239
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version >= 1.6.0 < 1.6.35
Pivotal Software ≫ Cloud Foundry Elastic Runtime Version >= 1.7.0 < 1.7.13
Pivotal Software ≫ Cloud Foundry Uaa Version <= 3.4.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.03% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://github.com/cloudfoundry/cf-release/releases/tag/v240
Third Party Advisory
Release Notes
https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3
Third Party Advisory
Release Notes
https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3
Third Party Advisory
Release Notes
https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6
Third Party Advisory
Release Notes
https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3
Third Party Advisory
Release Notes
https://github.com/cloudfoundry/uaa/releases/tag/3.4.2
Third Party Advisory
Release Notes
https://pivotal.io/security/cve-2016-5016
Vendor Advisory