CVE-2015-5171

EUVD-2022-4065
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
cloudfoundrycf-release
𝑥
< 216
pivotal_softwarecloud_foundry_elastic_runtime
𝑥
< 1.7.0
pivotal_softwarecloud_foundry_uaa
𝑥
< 2.5.2
𝑥
= Vulnerable software versions