PT-2017-8327 · Cloud Foundry+1 · Login-Server+3

Published

2017-05-25

·

Updated

2022-05-13

·

CVE-2016-3084

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry versions prior to v236 UAA versions prior to v3.3.0 UAA versions prior to v10 Login-server all versions Pivotal Elastic Runtime versions prior to 1.7.2
Description The UAA reset password flow is vulnerable to a brute force attack due to multiple active codes at a given time. This issue is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
Recommendations For Cloud Foundry versions prior to v236, update to a version later than v236. For UAA versions prior to v3.3.0, update to a version later than v3.3.0. For UAA versions prior to v10, update to a version later than v10. For Login-server all versions, consider disabling the UAA internal user store for authentication until a patch is available. For Pivotal Elastic Runtime versions prior to 1.7.2, update to a version later than 1.7.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3084
GHSA-FM5C-2RWC-887W

Affected Products

Cloud Foundry
Login-Server
Pivotal Elastic Runtime
Uaa