CVE-2016-3085

MEDIUM

Apache Cloudstack - Security Feature Bypass

Title source: rule

Description

Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.

Scores

CVSS v3 6.5
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

Classification

CWE
CWE-287 CWE-254
Status draft

Affected Products (7)

apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack

Timeline

Published Jun 10, 2016
Tracked Since Feb 18, 2026