PT-2016-7026 · Cloud Foundry · Uaa+1
David King
+2
·
Publicado
2016-12-23
·
Atualizado
2021-08-06
·
CVE-2016-6659
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry versions prior to 248
UAA versions 2.x prior to 2.7.4.12
UAA versions 3.x prior to 3.6.5
UAA versions 3.7.x through 3.9.x prior to 3.9.3
UAA bosh release (aka uaa-release) versions prior to 13.9 for UAA 3.6.5
UAA bosh release (aka uaa-release) versions prior to 24 for UAA 3.9.3
Description
The issue allows attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
Recommendations
For Cloud Foundry versions prior to 248, update to version 248 or later.
For UAA versions 2.x prior to 2.7.4.12, update to version 2.7.4.12 or later.
For UAA versions 3.x prior to 3.6.5, update to version 3.6.5 or later.
For UAA versions 3.7.x through 3.9.x prior to 3.9.3, update to version 3.9.3 or later.
For UAA bosh release (aka uaa-release) versions prior to 13.9 for UAA 3.6.5, update to version 13.9 or later.
For UAA bosh release (aka uaa-release) versions prior to 24 for UAA 3.9.3, update to version 24 or later.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloud Foundry
Uaa