Page 2 of 12 results (0.002 seconds)

CVSS: 5.3EPSS: 0%CPEs: 97EXPL: 0

30 Sep 2016 — The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 mishandles redirect_uri subdomains, which allows remote attackers to obtain implicit access tokens via a modified subdomain. La implementación de autorización OAuth en Pivotal Cloud Fo... • http://www.securityfocus.com/bid/93246 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVSS: 6.1EPSS: 0%CPEs: 16EXPL: 0

18 Sep 2016 — Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Pivotal Cloud Foundry (PCF) Ops Manager en versiones anteriores a 1.6.17 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • https://pivotal.io/security/cve-2016-0927 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •