← Back

CVE-2016-4468

nvd nist
Published: Apr 11, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Affected (48)

1 product
Cloud Foundry Uaa Bosh
Cloud Foundry
Cloud Foundry Elastic Runtime
Cloud Foundry Ops Manager
Cloud Foundry Uaa
Configuration A
48 vulnerable
Vulnerable SoftwareAffected Versions
Up to 12.0
Up to 237.0
Pivotal Software
Version 1.6.0
Version 1.6.10
Version 1.6.11
Version 1.6.12
Version 1.6.13
Version 1.6.14
Version 1.6.15
Version 1.6.17
Version 1.6.18
Version 1.6.19
Version 1.6.1
Version 1.6.20
Version 1.6.21
Version 1.6.22
Version 1.6.23
Version 1.6.25
Version 1.6.26
Version 1.6.27
Version 1.6.28
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6.6
Version 1.6.7
Version 1.6.8
Version 1.6.9
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.8.0
Pivotal Software
Version 1.7.0
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.7.8
Up to 3.4.0

References (4)

Timeline

No history available yet.