CVE-2016-4468
- EPSS 1.33%
- Veröffentlicht 11.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manage...
CVE-2016-6657
- EPSS 0.19%
- Veröffentlicht 16.12.2016 09:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runtime 1.8.x versions to 1.8.12 or later. Upgrade PCF ...
CVE-2016-6651
- EPSS 0.58%
- Veröffentlicht 30.09.2016 00:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x befo...
CVE-2016-6637
- EPSS 0.12%
- Veröffentlicht 30.09.2016 00:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x ...
CVE-2016-6636
- EPSS 0.24%
- Veröffentlicht 30.09.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1...
CVE-2016-0927
- EPSS 0.25%
- Veröffentlicht 18.09.2016 02:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-0926
- EPSS 0.32%
- Veröffentlicht 18.09.2016 02:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interact...
CVE-2016-0896
- EPSS 0.14%
- Veröffentlicht 18.09.2016 02:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging ...