Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-6659

Опубликовано: 23 дек. 2016
Источник: nvd
CVSS3: 8.1
CVSS2: 2.6
EPSS Низкий

Описание

Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:*
Версия до 23.0 (включая)
cpe:2.3:a:pivotal_software:cloud_foundry:*:*:*:*:*:*:*:*
Версия до 247.0 (включая)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*
Версия до 3.9.2 (включая)

EPSS

Процентиль: 55%
0.00323
Низкий

8.1 High

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.

EPSS

Процентиль: 55%
0.00323
Низкий

8.1 High

CVSS3

2.6 Low

CVSS2

Дефекты

CWE-287