CVE-2017-4960
- EPSS 0.45%
- Published 10.03.2017 01:59:00
- Last modified 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
CVE-2016-6659
- EPSS 0.32%
- Published 23.12.2016 05:59:00
- Last modified 12.04.2025 10:46:40
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UA...
CVE-2016-6651
- EPSS 0.58%
- Published 30.09.2016 00:59:04
- Last modified 12.04.2025 10:46:40
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x befo...
CVE-2016-6637
- EPSS 0.12%
- Published 30.09.2016 00:59:01
- Last modified 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x ...
CVE-2016-6636
- EPSS 0.24%
- Published 30.09.2016 00:59:00
- Last modified 12.04.2025 10:46:40
The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1...