Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2016-0732 Details

Description

The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://pivotal.io/security/cve-2016-0732 CVEMitigationVendor Advisory
https://pivotal.io/security/cve-2016-0732 [email protected]MitigationVendor Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-269Improper Privilege Management[email protected]

Affected Products

ProductVersions
cloudfoundry cf-release
>= 208, <= 229

CPE

  • cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cloudfoundry user account and authentication
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0

CPE

  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.0.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.3:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.4:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.5:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.5.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.5.3:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.2.6:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.3.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.3.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.5.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.5.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.6.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.0.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.0.3:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.1:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:user_account_and_authentication:2.7.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cloudfoundry uaa-release
2
3
4

CPE

  • cpe:2.3:a:cloudfoundry:uaa-release:2:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:uaa-release:3:*:*:*:*:*:*:*
  • cpe:2.3:a:cloudfoundry:uaa-release:4:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
pivotal elastic runtime
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4

CPE

  • cpe:2.3:a:pivotal:elastic_runtime:1.6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.2:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.3:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.4:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.5:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.6:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.7:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.8:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.9:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.10:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.11:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.12:*:*:*:*:*:*:*
  • cpe:2.3:a:pivotal:elastic_runtime:1.6.13:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

75 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2016-0732
NVD Published Date:
Sep 7, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2016-0732 Details - Not Deferred