Unknown
CVE-2016-2165
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2016-2165
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- cf-release,
- cloud foundry elastic runtime,
- cloud foundry elastic runtime 1.6.0,
- cloud foundry elastic runtime 1.6.1,
- cloud foundry elastic runtime 1.6.10,
- cloud foundry elastic runtime 1.6.11,
- cloud foundry elastic runtime 1.6.12,
- cloud foundry elastic runtime 1.6.13,
- cloud foundry elastic runtime 1.6.14,
- cloud foundry elastic runtime 1.6.15,
- cloud foundry elastic runtime 1.6.16,
- cloud foundry elastic runtime 1.6.17,
- cloud foundry elastic runtime 1.6.18,
- cloud foundry elastic runtime 1.6.19,
- cloud foundry elastic runtime 1.6.2,
- cloud foundry elastic runtime 1.6.3,
- cloud foundry elastic runtime 1.6.4,
- cloud foundry elastic runtime 1.6.5,
- cloud foundry elastic runtime 1.6.6,
- cloud foundry elastic runtime 1.6.7,
- cloud foundry elastic runtime 1.6.8,
- cloud foundry elastic runtime 1.6.9
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: