Cloudfoundry

Uaa

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 06.10.2026 07:06:18
  • Zuletzt bearbeitet 06.10.2026 16:00:36

Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenti...

  • EPSS 0.35%
  • Veröffentlicht 06.10.2026 06:54:10
  • Zuletzt bearbeitet 06.10.2026 16:00:36

Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by...

  • EPSS 0.3%
  • Veröffentlicht 25.08.2026 11:05:11
  • Zuletzt bearbeitet 28.09.2026 23:10:00

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restricti...

  • EPSS 0.13%
  • Veröffentlicht 09.07.2026 06:26:02
  • Zuletzt bearbeitet 09.07.2026 16:39:17

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and retu...

  • EPSS 0.13%
  • Veröffentlicht 11.06.2026 20:03:22
  • Zuletzt bearbeitet 12.06.2026 16:06:17

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and brows...

  • EPSS 0.22%
  • Veröffentlicht 05.03.2026 20:40:27
  • Zuletzt bearbeitet 10.05.2026 14:16:48

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.

  • EPSS 0.2%
  • Veröffentlicht 13.05.2025 05:14:40
  • Zuletzt bearbeitet 11.07.2025 15:50:39

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

  • EPSS 0.19%
  • Veröffentlicht 31.01.2025 06:15:30
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

  • EPSS 0.13%
  • Veröffentlicht 18.07.2024 19:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This...