Show filters
12 Total Results
Displaying 11-12 of 12
Sort by:
Attacker Value
Unknown
UAA SCIM Filter XSS
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
0
Attacker Value
Unknown
CVE-2016-0732
Disclosure Date: September 07, 2017 (last updated November 26, 2024)
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
0