Known vulnerabilities in Bosh Release for the UAA

Software CPE: cpe:2.3:a:cloud_foundry_foundation:pivotal_cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Bosh Release for the UAA Bosh Release for the UAA is affected by 12 known vulnerabilities: 1 critical, 5 high, 2 medium, 4 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86983 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-1597
CWE-89 High
No
No
74.5.105 04.03.2024 SB2024030405
SB2024030406
SB2024030427
and 47 more
#VU86695 - Server-Side Request Forgery (SSRF)
CVE-2024-22243
CWE-918 Medium
Available
No
74.5.105 21.02.2024 SB2024022140
SB2024030406
SB2024030529
and 45 more
#VU65495 - Improper input validation
CVE-2022-34169
CWE-20 High
Available
No
75.22.0 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 137 more
#VU63480 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-24891
CWE-79 Low
No
No
75.20.0 20.05.2022 SB2022052008
SB2022052009
SB2022052010
and 5 more
#VU63479 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-23457
CWE-22 High
No
No
75.20.0 20.05.2022 SB2022052008
SB2022052009
SB2022052010
and 11 more
#VU63345 - Improper Authorization
CVE-2022-22978
CWE-285 High
Available
No
75.20.0 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 20 more
#VU63342 - Integer overflow
CVE-2022-22976
CWE-190 Low
Available
No
75.20.0 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 7 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
75.17.0 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Available
Exploited
75.18.0 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU19130 - Improper Authentication
CVE-2016-6659
CWE-287 High
No
No
24 10.07.2019 SB2016120703
#VU712 - Cross-Site Request Forgery (CSRF)
CVE-2016-6637
CWE-352 Low
No
No
- 30.09.2016 SB2016093007
#VU713 - Improper input validation
CVE-2016-6636
CWE-20 Low
No
No
- 30.09.2016 SB2016093008