CVE-2016-0732

HIGH

Pivotal Cloud Foundry <229 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2016-0732

Scores

CVSS v3 8.8
EPSS 0.0115
EPSS Percentile 63.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (50)
cloudfoundry/cf-release 208 - 229
cloudfoundry/uaa-release 2
cloudfoundry/uaa-release 3
cloudfoundry/uaa-release 4
cloudfoundry/user_account_and_authentication 2.0.0
cloudfoundry/user_account_and_authentication 2.0.1
cloudfoundry/user_account_and_authentication 2.0.2
cloudfoundry/user_account_and_authentication 2.0.3
cloudfoundry/user_account_and_authentication 2.1.0
cloudfoundry/user_account_and_authentication 2.2.0
... and 40 more
Published Sep 07, 2017
Tracked Since Feb 18, 2026