CVE-2017-4960

UnknownEPSS 1.58%

Last modified

CVE-2017-4960 is a vulnerability of currently unknown severity. An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.. EPSS estimates a 1.58% chance of exploitation in the next 30 days.

Description

An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.

Metrics

EPSS Probability
1.58%

72.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CloudfoundryCloud Foundry Uaa Bosh21
CloudfoundryCloud Foundry Uaa Bosh22
CloudfoundryCloud Foundry Uaa Bosh23
CloudfoundryCloud Foundry Uaa Bosh24
CloudfoundryCloud Foundry Uaa Bosh24.1
CloudfoundryCloud Foundry Uaa Bosh24.2
CloudfoundryCloud Foundry Uaa Bosh24.3
CloudfoundryCloud Foundry Uaa Bosh24.4
CloudfoundryCloud Foundry Uaa Bosh24.5
CloudfoundryCloud Foundry Uaa Bosh24.6
CloudfoundryCloud Foundry Uaa Bosh25
CloudfoundryCloud Foundry Uaa Bosh26
Pivotal SoftwareCloud Foundry247.0
Pivotal SoftwareCloud Foundry248.0
Pivotal SoftwareCloud Foundry249.0
Pivotal SoftwareCloud Foundry250.0
Pivotal SoftwareCloud Foundry251.0
Pivotal SoftwareCloud Foundry252.0
Pivotal SoftwareCloud Foundry Uaa3.9.0
Pivotal SoftwareCloud Foundry Uaa3.9.1
Pivotal SoftwareCloud Foundry Uaa3.9.2
Pivotal SoftwareCloud Foundry Uaa3.9.3
Pivotal SoftwareCloud Foundry Uaa3.9.4
Pivotal SoftwareCloud Foundry Uaa3.9.5
Pivotal SoftwareCloud Foundry Uaa3.9.6
Pivotal SoftwareCloud Foundry Uaa3.9.7
Pivotal SoftwareCloud Foundry Uaa3.9.8
Pivotal SoftwareCloud Foundry Uaa3.10.0
Pivotal SoftwareCloud Foundry Uaa3.11.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-4960?
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
How severe is CVE-2017-4960?
Severity scoring for CVE-2017-4960 is pending analysis. The EPSS model estimates a 1.58% probability of exploitation in the next 30 days.
How do I fix CVE-2017-4960?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-4960?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST