Vulnerability Name:

CVE-2016-4468 (CCN-115822)

Assigned:2016-06-30
Published:2016-06-30
Updated:2021-08-06
Summary:SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2016-4468

Source: XF
Type: UNKNOWN
cloud-foundry-cve20164468-sql-injection(115822)

Source: MLIST
Type: Patch, Vendor Advisory
[cf-dev] 20160630 CVE-2016-4468 UAA SQL Injection

Source: CCN
Type: Pivotal Web site
CVE-2016-4468 UAA SQL Injection

Source: CONFIRM
Type: Mitigation, Patch, Vendor Advisory
https://pivotal.io/security/cve-2016-4468

Vulnerable Configuration:Configuration 1:
  • cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.27:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.28:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.8.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry:*:*:*:*:*:*:*:* (Version <= 237.0)
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* (Version <= 3.4.0)
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.17:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.20:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.23:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.18:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.8:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.7:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.26:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.19:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.2:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.21:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:* (Version <= 12.0)
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.6:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.22:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.25:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.7:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_elastic_runtime:1.7.3:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_ops_manager:1.7.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    pivotal_software cloud foundry elastic runtime 1.6.1
    pivotal_software cloud foundry elastic runtime 1.6.10
    pivotal_software cloud foundry elastic runtime 1.6.11
    pivotal_software cloud foundry elastic runtime 1.6.12
    pivotal_software cloud foundry elastic runtime 1.6.27
    pivotal_software cloud foundry elastic runtime 1.6.28
    pivotal_software cloud foundry elastic runtime 1.6.3
    pivotal_software cloud foundry elastic runtime 1.6.4
    pivotal_software cloud foundry elastic runtime 1.8.0
    pivotal_software cloud foundry ops manager 1.7.0
    pivotal_software cloud foundry ops manager 1.7.1
    pivotal_software cloud foundry elastic runtime 1.6.5
    pivotal_software cloud foundry *
    pivotal_software cloud foundry uaa *
    pivotal_software cloud foundry elastic runtime 1.6.7
    pivotal_software cloud foundry elastic runtime 1.7.1
    pivotal_software cloud foundry elastic runtime 1.6.9
    pivotal_software cloud foundry elastic runtime 1.6.14
    pivotal_software cloud foundry elastic runtime 1.6.17
    pivotal_software cloud foundry elastic runtime 1.7.4
    pivotal_software cloud foundry elastic runtime 1.6.20
    pivotal_software cloud foundry elastic runtime 1.6.2
    pivotal_software cloud foundry elastic runtime 1.6.23
    pivotal_software cloud foundry elastic runtime 1.7.0
    pivotal_software cloud foundry ops manager 1.7.2
    pivotal_software cloud foundry elastic runtime 1.6.18
    pivotal_software cloud foundry ops manager 1.7.8
    pivotal_software cloud foundry ops manager 1.7.7
    pivotal_software cloud foundry elastic runtime 1.6.26
    pivotal_software cloud foundry elastic runtime 1.6.19
    pivotal_software cloud foundry elastic runtime 1.7.2
    pivotal_software cloud foundry elastic runtime 1.6.21
    cloudfoundry cloud foundry uaa bosh *
    pivotal_software cloud foundry elastic runtime 1.6.13
    pivotal_software cloud foundry elastic runtime 1.7.6
    pivotal_software cloud foundry elastic runtime 1.6.6
    pivotal_software cloud foundry ops manager 1.7.3
    pivotal_software cloud foundry ops manager 1.7.4
    pivotal_software cloud foundry elastic runtime 1.6.22
    pivotal_software cloud foundry elastic runtime 1.6.25
    pivotal_software cloud foundry elastic runtime 1.6.0
    pivotal_software cloud foundry elastic runtime 1.7.7
    pivotal_software cloud foundry ops manager 1.7.5
    pivotal_software cloud foundry elastic runtime 1.6.15
    pivotal_software cloud foundry elastic runtime 1.7.5
    pivotal_software cloud foundry elastic runtime 1.6.8
    pivotal_software cloud foundry elastic runtime 1.7.3
    pivotal_software cloud foundry ops manager 1.7.6