SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-15754

In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username…

HIGH 8.8EPSS 1.78%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

CVSS 3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.78% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
pivotal software/cloud foundry uaa-release
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.