CVE-2016-4468: SQL Injection
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4468?
CVE-2016-4468 is classified as a medium severity SQL injection vulnerability.
How do I fix CVE-2016-4468?
To fix CVE-2016-4468, upgrade to Pivotal Cloud Foundry versions 238 or later, or update UAA and Elastic Runtime to their respective patched versions.
What products are affected by CVE-2016-4468?
CVE-2016-4468 affects several components of Pivotal Cloud Foundry including UAA, Elastic Runtime, and Ops Manager before specified versions.
What are the potential impacts of CVE-2016-4468?
Exploitation of CVE-2016-4468 could allow remote authenticated attackers to execute arbitrary SQL commands.
Is CVE-2016-4468 remote exploitable?
Yes, CVE-2016-4468 can be exploited remotely by authenticated users.