CVE-2017-4972: SQL Injection
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. An attacker can use a blind SQL injection attack to query the contents of the UAA database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4972?
CVE-2017-4972 is considered to have a high severity due to potential unauthorized access vulnerabilities.
How do I fix CVE-2017-4972?
To address CVE-2017-4972, upgrade to Cloud Foundry UAA release versions 2.7.4.14 or later, or any 3.x versions 3.6.8 or later.
Which Cloud Foundry versions are affected by CVE-2017-4972?
CVE-2017-4972 affects Cloud Foundry Foundation cf-release versions prior to v257 and various UAA versions before specific patches.
Is CVE-2017-4972 still a risk?
Yes, if affected versions are still in use without the recommended updates, CVE-2017-4972 remains a significant security risk.
What systems could be impacted by CVE-2017-4972?
CVE-2017-4972 can impact systems running older versions of Cloud Foundry CF Release and UAA, especially those mentioned in the vulnerability details.