CVE Vulnerabilities

CVE-2016-5016

Improper Certificate Validation

Published: Apr 24, 2017 | Modified: Feb 26, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Cloud_foundry Pivotal_software * 239 (including)
Cloud_foundry_elastic_runtime Pivotal_software 1.6.0 (including) 1.6.35 (excluding)
Cloud_foundry_elastic_runtime Pivotal_software 1.7.0 (including) 1.7.13 (excluding)
Cloud_foundry_uaa Pivotal_software * 3.4.1 (including)
Cloud_foundry_uaa-release Pivotal_software * 12.2 (including)

Potential Mitigations

References