← Back

CVE-2017-4963

nvd nist
Published: Jun 13, 2017Modified: May 13, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.

Affected (4)

Cloud Foundry Cf Release
Cloud Foundry Uaa
Cloud Foundry Uaa Release
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Up to 252
Pivotal Software
From 2.0.0 to 2.7.4.12
From 3.0.0 to 3.11.0
Up to 26

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.