Known vulnerabilities in Cloud Foundry UAA

Software CPE: cpe:2.3:a:cloud_foundry_foundation:cloud_foundry_uaa:*:*:*:*:*:*:*:*
Total vulnerabilities: 37
Public exploits: 6
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cloud Foundry UAA Cloud Foundry UAA is affected by 37 known vulnerabilities: 1 critical, 12 high, 15 medium, 9 low Critical High Medium Low

Vulnerabilities (37)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU96018 - Improper input validation
CVE-2024-38809
CWE-20 Medium
No
No
77.15.0 14.08.2024 SB2024081479
SB2024091920
SB2024100804
and 26 more
#VU82276 - Allocation of Resources Without Limits or Throttling
CVE-2023-5072
CWE-770 Medium
No
No
76.23.0 20.10.2023 SB2023102017
SB2023102018
SB2023113056
and 97 more
#VU76427 - Resource Management Errors
CVE-2023-20883
CWE-399 Medium
No
No
76.13.0 23.05.2023 SB2023052310
SB2023052311
SB2023061548
and 42 more
#VU75409 - Improper input validation
CVE-2023-20863
CWE-20 Medium
No
No
76.10.0 21.04.2023 SB2023042131
SB2023042132
SB2023050511
and 88 more
#VU75408 - Security Features
CVE-2023-20862
CWE-254 Medium
No
No
76.10.0 21.04.2023 SB2023042130
SB2023042132
SB2023053121
and 20 more
#VU75407 - Security Features
CVE-2023-20873
CWE-254 Medium
No
No
76.10.0 21.04.2023 SB2023042129
SB2023042132
SB2023060816
and 16 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
76.2.0 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU66747 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-31197
CWE-89 High
No
No
75.23.0 24.08.2022 SB2022082432
SB2022082543
SB2022090901
and 27 more
#VU65495 - Improper input validation
CVE-2022-34169
CWE-20 High
Available
No
75.22.0 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 137 more
#VU63480 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-24891
CWE-79 Low
No
No
75.20.0 20.05.2022 SB2022052008
SB2022052009
SB2022052010
and 5 more
#VU63479 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-23457
CWE-22 High
No
No
75.20.0 20.05.2022 SB2022052008
SB2022052009
SB2022052010
and 11 more
#VU63345 - Improper Authorization
CVE-2022-22978
CWE-285 High
Available
No
75.20.0 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 20 more
#VU63342 - Integer overflow
CVE-2022-22976
CWE-190 Low
Available
No
75.20.0 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 7 more
#VU62472 - Resource exhaustion
CVE-2022-22969
CWE-400 Medium
No
No
75.19.0 21.04.2022 SB2022042129
SB2022042903
SB2022071933
and 2 more
#VU62314 - Security Features
CVE-2022-22968
CWE-254 Medium
Available
No
75.19.0 14.04.2022 SB2022041405
SB2022042903
SB2022060324
and 31 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
75.17.0 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Available
Exploited
75.18.0 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU25807 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-1935
CWE-444 Medium
No
No
74.16.0 06.03.2020 SB2020022111
SB2020031401
SB2020031402
and 15 more
#VU25806 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-17569
CWE-444 Medium
No
No
74.16.0 06.03.2020 SB2020022111
SB2020031401
SB2020031402
and 6 more
#VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1938
CWE-22 High
Available
Exploited
74.16.0 21.02.2020 SB2020022111
SB2020031401
SB2020031402
and 31 more


Showing elements 1 - 20 out of 37