CVE-2026-59357
- EPSS 0.19%
- Veröffentlicht 06.10.2026 07:06:18
- Zuletzt bearbeitet 06.10.2026 16:00:36
Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenti...
CVE-2026-59358
- EPSS 0.35%
- Veröffentlicht 06.10.2026 06:54:10
- Zuletzt bearbeitet 06.10.2026 16:00:36
Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by...
CVE-2026-59335
- EPSS 0.3%
- Veröffentlicht 25.08.2026 11:05:11
- Zuletzt bearbeitet 28.09.2026 23:10:00
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restricti...
CVE-2026-47840
- EPSS 0.13%
- Veröffentlicht 09.07.2026 06:26:02
- Zuletzt bearbeitet 09.07.2026 16:39:17
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and retu...
- EPSS 0.13%
- Veröffentlicht 11.06.2026 20:03:22
- Zuletzt bearbeitet 12.06.2026 16:06:17
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and brows...
CVE-2026-22723
- EPSS 0.22%
- Veröffentlicht 05.03.2026 20:40:27
- Zuletzt bearbeitet 10.05.2026 14:16:48
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
CVE-2025-22246
- EPSS 0.2%
- Veröffentlicht 13.05.2025 05:14:40
- Zuletzt bearbeitet 11.07.2025 15:50:39
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
CVE-2025-22216
- EPSS 0.19%
- Veröffentlicht 31.01.2025 06:15:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
CVE-2024-38806
- EPSS 0.13%
- Veröffentlicht 18.07.2024 19:15:12
- Zuletzt bearbeitet 15.04.2026 00:35:42
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This...