CVE-2016-0781

UnknownEPSS 0.66%

Last modified

CVE-2016-0781 is a vulnerability of currently unknown severity. The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.

Metrics

EPSS Probability
0.66%

46.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CloudfoundryCloud Foundry Uaa Bosh2
CloudfoundryCloud Foundry Uaa Bosh3
CloudfoundryCloud Foundry Uaa Bosh4
CloudfoundryCloud Foundry Uaa Bosh5
CloudfoundryCloud Foundry Uaa Bosh6
CloudfoundryCloud Foundry Uaa Bosh7
Pivotal SoftwareCloud Foundry208
Pivotal SoftwareCloud Foundry209
Pivotal SoftwareCloud Foundry210
Pivotal SoftwareCloud Foundry211
Pivotal SoftwareCloud Foundry212
Pivotal SoftwareCloud Foundry213
Pivotal SoftwareCloud Foundry214
Pivotal SoftwareCloud Foundry215
Pivotal SoftwareCloud Foundry216
Pivotal SoftwareCloud Foundry217
Pivotal SoftwareCloud Foundry218
Pivotal SoftwareCloud Foundry219
Pivotal SoftwareCloud Foundry220
Pivotal SoftwareCloud Foundry221
Pivotal SoftwareCloud Foundry222
Pivotal SoftwareCloud Foundry223
Pivotal SoftwareCloud Foundry224
Pivotal SoftwareCloud Foundry225
Pivotal SoftwareCloud Foundry226
Pivotal SoftwareCloud Foundry227
Pivotal SoftwareCloud Foundry228
Pivotal SoftwareCloud Foundry229
Pivotal SoftwareCloud Foundry230
Pivotal SoftwareCloud Foundry231
Pivotal SoftwareCloud Foundry241
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.0
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.1
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.2
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.3
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.4
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.5
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.6
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.7
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.8
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.9
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.10
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.11
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.12
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.13
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.14
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.15
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.16
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.17
Pivotal SoftwareCloud Foundry Elastic Runtime1.6.18

Showing 50 of 57 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-0781?
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
How severe is CVE-2016-0781?
Severity scoring for CVE-2016-0781 is pending analysis. The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2016-0781?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-0781?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST