CVE-2017-4972

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. An attacker can use a blind SQL injection attack to query the contents of the UAA database.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
cloudfoundrycf-release
𝑥
≤ 256
cloudfoundrycloud_foundry_uaa_bosh
𝑥
≤ 29
cloudfoundrycloud_foundry_uaa_bosh
13.1
cloudfoundrycloud_foundry_uaa_bosh
13.2
cloudfoundrycloud_foundry_uaa_bosh
13.3
cloudfoundrycloud_foundry_uaa_bosh
13.4
cloudfoundrycloud_foundry_uaa_bosh
13.5
cloudfoundrycloud_foundry_uaa_bosh
13.6
cloudfoundrycloud_foundry_uaa_bosh
13.7
cloudfoundrycloud_foundry_uaa_bosh
13.8
cloudfoundrycloud_foundry_uaa_bosh
13.9
cloudfoundrycloud_foundry_uaa_bosh
13.10
cloudfoundrycloud_foundry_uaa_bosh
13.11
cloudfoundrycloud_foundry_uaa_bosh
24.1
cloudfoundrycloud_foundry_uaa_bosh
24.2
cloudfoundrycloud_foundry_uaa_bosh
24.3
cloudfoundrycloud_foundry_uaa_bosh
24.4
cloudfoundrycloud_foundry_uaa_bosh
24.5
cloudfoundrycloud_foundry_uaa_bosh
24.6
cloudfoundrycloud_foundry_uaa_bosh
30.1
cloudfoundrycloud_foundry_uaa_bosh
30.2
cloudfoundrycloud_foundry_uaa_bosh
30.3
pivotal_softwarecloud_foundry_uaa
𝑥
≤ 3.15.0
pivotal_softwarecloud_foundry_uaa
2.2.5.4
pivotal_softwarecloud_foundry_uaa
2.7.1
pivotal_softwarecloud_foundry_uaa
2.7.2
pivotal_softwarecloud_foundry_uaa
2.7.3
pivotal_softwarecloud_foundry_uaa
2.7.4
pivotal_softwarecloud_foundry_uaa
2.7.4.1
pivotal_softwarecloud_foundry_uaa
2.7.4.2
pivotal_softwarecloud_foundry_uaa
2.7.4.3
pivotal_softwarecloud_foundry_uaa
2.7.4.4
pivotal_softwarecloud_foundry_uaa
2.7.4.5
pivotal_softwarecloud_foundry_uaa
2.7.4.6
pivotal_softwarecloud_foundry_uaa
2.7.4.7
pivotal_softwarecloud_foundry_uaa
2.7.4.8
pivotal_softwarecloud_foundry_uaa
2.7.4.9
pivotal_softwarecloud_foundry_uaa
2.7.4.11
pivotal_softwarecloud_foundry_uaa
2.7.4.12
pivotal_softwarecloud_foundry_uaa
2.7.4.13
pivotal_softwarecloud_foundry_uaa
3.6.1
pivotal_softwarecloud_foundry_uaa
3.6.2
pivotal_softwarecloud_foundry_uaa
3.6.3
pivotal_softwarecloud_foundry_uaa
3.6.4
pivotal_softwarecloud_foundry_uaa
3.6.5
pivotal_softwarecloud_foundry_uaa
3.6.6
pivotal_softwarecloud_foundry_uaa
3.6.7
pivotal_softwarecloud_foundry_uaa
3.6.8
pivotal_softwarecloud_foundry_uaa
3.6.9
pivotal_softwarecloud_foundry_uaa
3.9.1
pivotal_softwarecloud_foundry_uaa
3.9.2
pivotal_softwarecloud_foundry_uaa
3.9.3
pivotal_softwarecloud_foundry_uaa
3.9.4
pivotal_softwarecloud_foundry_uaa
3.9.5
pivotal_softwarecloud_foundry_uaa
3.9.6
pivotal_softwarecloud_foundry_uaa
3.9.7
pivotal_softwarecloud_foundry_uaa
3.9.8
pivotal_softwarecloud_foundry_uaa
3.9.9
pivotal_softwarecloud_foundry_uaa
3.9.12
pivotal_softwarecloud_foundry_uaa
3.9.13
𝑥
= Vulnerable software versions