CVE-2015-5172

EUVD-2022-3609
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
cloudfoundrycf-release
𝑥
< 216
pivotal_softwarecloud_foundry_elastic_runtime
𝑥
< 1.7.0
pivotal_softwarecloud_foundry_uaa
𝑥
< 2.5.2
𝑥
= Vulnerable software versions