Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Cloudfoundry Cf-deploymentPivotal Software Cloud Foundry UAA23/10/201917/6/2026
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.
ModificadaAlta (7.5)1.1%—Pivotal Software Application ServicePivotal Software Cloud Foundry UAAPivotal Software Operations Manager5/8/201917/6/2026
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
ModificadaMedia (5.4)1.1%—Pivotal Software Cloud Foundry UAA18/7/201917/6/2026
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
ModificadaMedia (4.3)1.0%—Pivotal Software Cloud Foundry Uaa-release11/7/201917/6/2026
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other…
ModificadaAlta (8.8)1.1%—Pivotal Software Cloud Foundry Uaa-release19/6/201917/6/2026
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially…
ModificadaAlta (8.8)1.8%—Pivotal Software Cloud Foundry Uaa-release13/12/201817/6/2026
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of…
ModificadaAlta (8.8)1.7%—Pivotal Software Cloud Foundry UAAPivotal Software Cloudfoundry UAA Release19/11/201817/6/2026
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
ModificadaAlta (7.5)1.1%—Pivotal Software Cloud Foundry UAA24/7/201817/6/2026
Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid refresh token in lieu of an access token. Refresh tokens by design have a longer expiration time than…
ModificadaMedia (6.1)0.85%—Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release25/6/201817/6/2026
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote…
ModificadaAlta (7.2)1.3%—Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releaseCloudfoundry Cf-deployment15/5/201817/6/2026
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the…
ModificadaAlta (8.8)1.0%—Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releasePivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry Cf-deployment1/2/201817/6/2026
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the…
ModificadaAlta (8.8)1.0%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
ModificadaAlta (8.8)0.76%—Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA24/10/201717/6/2026
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
ModificadaMedia (6.6)0.88%—Pivotal Software Cloud Foundry UAACloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CF10/7/201717/6/2026
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to…
ModificadaAlta (7.5)1.1%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior…
ModificadaCrítica (9.8)1.2%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior…
ModificadaAlta (7.2)0.94%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions…
ModificadaMedia (6.5)0.97%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior…
ModificadaAlta (8.8)1.1%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior…
ModificadaAlta (7.5)1.1%—Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior…
ModificadaAlta (8.1)0.90%—Pivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release13/6/201717/6/2026
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect…
ModificadaAlta (8.1)1.2%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+125/5/201717/6/2026
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given…
ModificadaMedia (6.1)0.66%—Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+125/5/201717/6/2026
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes…