Lucene search

K
cvelistDellCVELIST:CVE-2017-4963
HistoryJun 13, 2017 - 6:00 a.m.

CVE-2017-4963

2017-06-1306:00:00
dell
www.cve.org

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.8%

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.

CNA Affected

[
  {
    "product": "Cloud Foundry Foundation",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cloud Foundry Foundation"
      }
    ]
  }
]

8.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.8%

Related for CVELIST:CVE-2017-4963