PT-2016-7026 · Cloud Foundry · Uaa+1
David King
+2
·
Published
2016-12-23
·
Updated
2021-08-06
·
CVE-2016-6659
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry versions prior to 248
UAA versions 2.x prior to 2.7.4.12
UAA versions 3.x prior to 3.6.5
UAA versions 3.7.x through 3.9.x prior to 3.9.3
UAA bosh release (aka uaa-release) versions prior to 13.9 for UAA 3.6.5
UAA bosh release (aka uaa-release) versions prior to 24 for UAA 3.9.3
Description
The issue allows attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
Recommendations
For Cloud Foundry versions prior to 248, update to version 248 or later.
For UAA versions 2.x prior to 2.7.4.12, update to version 2.7.4.12 or later.
For UAA versions 3.x prior to 3.6.5, update to version 3.6.5 or later.
For UAA versions 3.7.x through 3.9.x prior to 3.9.3, update to version 3.9.3 or later.
For UAA bosh release (aka uaa-release) versions prior to 13.9 for UAA 3.6.5, update to version 13.9 or later.
For UAA bosh release (aka uaa-release) versions prior to 24 for UAA 3.9.3, update to version 24 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry
Uaa