TROYANOSYVIRUS
Back to CVEs

CVE-2015-5172

CRITICAL
9.8

Description

Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published10/24/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

cloudfoundry:cf-releasepivotal_software:cloud_foundry_elastic_runtimepivotal_software:cloud_foundry_uaa

Weaknesses (CWE)

CWE-640

References

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.