Unknown
CVE-2016-0781
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- cloud foundry 208,
- cloud foundry 209,
- cloud foundry 210,
- cloud foundry 211,
- cloud foundry 212,
- cloud foundry 213,
- cloud foundry 214,
- cloud foundry 215,
- cloud foundry 216,
- cloud foundry 217,
- cloud foundry 218,
- cloud foundry 219,
- cloud foundry 220,
- cloud foundry 221,
- cloud foundry 222,
- cloud foundry 223,
- cloud foundry 224,
- cloud foundry 225,
- cloud foundry 226,
- cloud foundry 227,
- cloud foundry 228,
- cloud foundry 229,
- cloud foundry 230,
- cloud foundry 231,
- cloud foundry 241,
- cloud foundry elastic runtime 1.6.0,
- cloud foundry elastic runtime 1.6.1,
- cloud foundry elastic runtime 1.6.10,
- cloud foundry elastic runtime 1.6.11,
- cloud foundry elastic runtime 1.6.12,
- cloud foundry elastic runtime 1.6.13,
- cloud foundry elastic runtime 1.6.14,
- cloud foundry elastic runtime 1.6.15,
- cloud foundry elastic runtime 1.6.16,
- cloud foundry elastic runtime 1.6.17,
- cloud foundry elastic runtime 1.6.18,
- cloud foundry elastic runtime 1.6.19,
- cloud foundry elastic runtime 1.6.2,
- cloud foundry elastic runtime 1.6.3,
- cloud foundry elastic runtime 1.6.4,
- cloud foundry elastic runtime 1.6.5,
- cloud foundry elastic runtime 1.6.6,
- cloud foundry elastic runtime 1.6.7,
- cloud foundry elastic runtime 1.6.8,
- cloud foundry elastic runtime 1.6.9,
- cloud foundry uaa,
- cloud foundry uaa 3.0.0,
- cloud foundry uaa 3.0.1,
- cloud foundry uaa 3.1.0,
- cloud foundry uaa 3.2.0,
- cloud foundry uaa bosh 2,
- cloud foundry uaa bosh 3,
- cloud foundry uaa bosh 4,
- cloud foundry uaa bosh 5,
- cloud foundry uaa bosh 6,
- cloud foundry uaa bosh 7,
- login-server -
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: