« Volver al listado

Cloudfoundry

Cloudfoundry UAA: vulnerabilidades y CVE

Cloudfoundry UAA tiene 6 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses5
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-59335Alta (8.7)0.53%—25 ago 2026
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority…
CVE-2026-47840Crítica (9.3)0.22%—9 jul 2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during…
CVE-2026-41005Crítica (9)0.16%—11 jun 2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer…
CVE-2026-40965Crítica (10)0.46%—1 jun 2026
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public…
CVE-2026-22734Alta (8.6)0.36%—17 abr 2026
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a…
CVE-2025-22216Media (5.4)0.19%—31 ene 2025
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078.001 Default Accounts1
  2. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Cloudfoundry