First published: Fri Sep 30 2016(Updated: )
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allows remote authenticated users to gain privileges by leveraging possession of a token.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloud Foundry UAA | <=16.0 | |
Cloud Foundry | <=242.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.21 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.22 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.23 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.25 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.26 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.27 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.28 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.29 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.30 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.31 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.32 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.33 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.34 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.35 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.36 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.37 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.38 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.39 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.16 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.0 | |
Pivotal Cloud Foundry Ops Manager | =1.7.0 | |
Pivotal Cloud Foundry Ops Manager | =1.7.1 | |
Pivotal Cloud Foundry Ops Manager | =1.7.2 | |
Pivotal Cloud Foundry Ops Manager | =1.7.3 | |
Pivotal Cloud Foundry Ops Manager | =1.7.4 | |
Pivotal Cloud Foundry Ops Manager | =1.7.5 | |
Pivotal Cloud Foundry Ops Manager | =1.7.6 | |
Pivotal Cloud Foundry Ops Manager | =1.7.7 | |
Pivotal Cloud Foundry Ops Manager | =1.7.8 | |
Pivotal Cloud Foundry Ops Manager | =1.7.9 | |
Pivotal Cloud Foundry Ops Manager | =1.7.10 | |
Pivotal Cloud Foundry Ops Manager | =1.7.11 | |
Pivotal Cloud Foundry Ops Manager | =1.7.12 | |
Pivotal Cloud Foundry Ops Manager | =1.8.0 | |
Cloud Foundry User Account and Authentication (UAA) | <=3.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6651 is classified as a medium severity vulnerability.
CVE-2016-6651 allows attackers to potentially gain unauthorized access to the OAuth token endpoint.
To mitigate CVE-2016-6651, upgrade to versions of Pivotal Cloud Foundry or UAA that are above the specified vulnerable versions.
CVE-2016-6651 affects Pivotal Cloud Foundry and UAA versions prior to the listed patches in the vulnerability details.
Yes, if you are using an affected version of Pivotal Cloud Foundry or its components, CVE-2016-6651 remains a security concern until patched.