← Back

CVE-2016-0781

nvd nist
Published: May 25, 2017Modified: May 13, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.

Affected (57)

1 product
Cloud Foundry Uaa Bosh
Cloud Foundry
Cloud Foundry Elastic Runtime
Cloud Foundry Uaa
Login Server
Configuration A
57 vulnerable
Vulnerable SoftwareAffected Versions
Cloudfoundry
Version 2
Version 3
Version 4
Version 5
Version 6
Version 7
Pivotal Software
Version 208
Version 209
Version 210
Version 211
Version 212
Version 213
Version 214
Version 215
Version 216
Version 217
Version 218
Version 219
Version 220
Version 221
Version 222
Version 223
Version 224
Version 225
Version 226
Version 227
Version 228
Version 229
Version 230
Version 231
Version 241
Pivotal Software
Version 1.6.0
Version 1.6.10
Version 1.6.11
Version 1.6.12
Version 1.6.13
Version 1.6.14
Version 1.6.15
Version 1.6.16
Version 1.6.17
Version 1.6.18
Version 1.6.19
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6.6
Version 1.6.7
Version 1.6.8
Version 1.6.9
Pivotal Software
Up to 2.7.4.1
Version 3.0.0
Version 3.0.1
Version 3.1.0
Version 3.2.0
All versions

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.