HIGH · 8.1

CVE-2016-3084

The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal ...

Vulnerability Description

The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.

CVSS Score

8.1

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CloudfoundryCloud Foundry Uaa Bosh<= 10
Pivotal SoftwareCloud Foundry<= 236
Pivotal SoftwareCloud Foundry Elastic Runtime<= 1.7.1
Pivotal SoftwareCloud Foundry Uaa<= 3.3.0
Pivotal SoftwareLogin-Server-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-3084?

CVE-2016-3084 is a vulnerability with a CVSS score of 8.1 (HIGH). The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal ...

How severe is CVE-2016-3084?

CVE-2016-3084 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-3084?

Check the references section above for vendor advisories and patch information. Affected products include: Cloudfoundry Cloud Foundry Uaa Bosh, Pivotal Software Cloud Foundry, Pivotal Software Cloud Foundry Elastic Runtime, Pivotal Software Cloud Foundry Uaa, Pivotal Software Login-Server.