// For flags

CVE-2016-0781

 

Severity Score

6.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.

Las páginas de aprobación OAuth de UAA en Cloud Foundry versiones v208 hasta v231, Login-server versiones v1.6 hasta v1.14, UAA versiones v2.0.0 hasta v2.7.4.1, UAA versiones v3.0.0 hasta v3.2.0, UAA-Release versiones v2 hasta v7 y Pivotal Elastic Runtime versiones 1.6.x anteriores a 1.6.20, son vulnerables a un ataque de tipo XSS mediante especificación de contenido de script java malicioso en los ámbitos OAuth (grupos SCIM) o descripciones de grupo SCIM.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-16 CVE Reserved
  • 2017-05-25 CVE Published
  • 2024-02-05 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL Tag Source
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
2
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "2"
-
Affected
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
3
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "3"
-
Affected
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
4
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "4"
-
Affected
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
5
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "5"
-
Affected
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
6
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "6"
-
Affected
Cloudfoundry
Search vendor "Cloudfoundry"
Cloud Foundry Uaa Bosh
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh"
7
Search vendor "Cloudfoundry" for product "Cloud Foundry Uaa Bosh" and version "7"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
208
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "208"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
209
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "209"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
210
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "210"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
211
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "211"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
212
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "212"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
213
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "213"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
214
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "214"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
215
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "215"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
216
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "216"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
217
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "217"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
218
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "218"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
219
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "219"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
220
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "220"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
221
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "221"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
222
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "222"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
223
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "223"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
224
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "224"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
225
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "225"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
226
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "226"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
227
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "227"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
228
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "228"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
229
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "229"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
230
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "230"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
231
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "231"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry
Search vendor "Pivotal Software" for product "Cloud Foundry"
241
Search vendor "Pivotal Software" for product "Cloud Foundry" and version "241"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.0
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.0"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.1
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.1"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.2
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.2"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.3
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.3"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.4
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.4"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.5
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.5"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.6
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.6"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.7
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.7"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.8
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.8"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.9
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.9"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.10
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.10"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.11
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.11"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.12
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.12"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.13
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.13"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.14
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.14"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.15
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.15"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.16
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.16"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.17
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.17"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.18
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.18"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Elastic Runtime
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime"
1.6.19
Search vendor "Pivotal Software" for product "Cloud Foundry Elastic Runtime" and version "1.6.19"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Uaa
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa"
<= 2.7.4.1
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " <= 2.7.4.1"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Uaa
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa"
3.0.0
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version "3.0.0"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Uaa
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa"
3.0.1
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version "3.0.1"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Uaa
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa"
3.1.0
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version "3.1.0"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Cloud Foundry Uaa
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa"
3.2.0
Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version "3.2.0"
-
Affected
Pivotal Software
Search vendor "Pivotal Software"
Login-server
Search vendor "Pivotal Software" for product "Login-server"
--
Affected