CVE-2016-0781 Information
Feb 14, 2021
cve
Description
The UAA OAuth approval pages in Cloud Foundry v208 to v231 Login-server v1.6 to v1.14 UAA v2.0.0 to v2.7.4.1 UAA v3.0.0 to v3.2.0 UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://pivotal.io/security/cve-2016-0781
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: