CVE-2016-3085
MEDIUMApache Cloudstack - Security Feature Bypass
Title source: ruleDescription
Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.
Scores
CVSS v3
6.5
EPSS
0.0027
EPSS Percentile
50.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Classification
CWE
CWE-287
CWE-254
Status
draft
Affected Products (7)
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
apache/cloudstack
Timeline
Published
Jun 10, 2016
Tracked Since
Feb 18, 2026