Description
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
References (1)
Core 1
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2016-0732
Scores
CVSS v3
8.8
EPSS
0.0115
EPSS Percentile
63.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (50)
cloudfoundry/cf-release
208 - 229
cloudfoundry/uaa-release
2
cloudfoundry/uaa-release
3
cloudfoundry/uaa-release
4
cloudfoundry/user_account_and_authentication
2.0.0
cloudfoundry/user_account_and_authentication
2.0.1
cloudfoundry/user_account_and_authentication
2.0.2
cloudfoundry/user_account_and_authentication
2.0.3
cloudfoundry/user_account_and_authentication
2.1.0
cloudfoundry/user_account_and_authentication
2.2.0
... and 40 more
Published
Sep 07, 2017
Tracked Since
Feb 18, 2026