CVE-2015-3189 — Weak Password Recovery Mechanism for Forgotten Password in Cf-release
Severity
3.7LOWNVD
EPSS
0.2%
top 60.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 25
Latest updateMay 13
Description
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4
Affected Packages4 packages
▶CVEListV5pivotal/cloud_foundryRuntime 1.4.5 or earlier, Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier+2
🔴Vulnerability Details
3CVEList▶
CVE-2015-3189: With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2↗2017-05-25