CVE-2016-5016 - CVE House
Back to Database
Status published Medium CVE-2016-5016

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account...

Vulnerability Description

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-5016

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

pivotal software

View all reports →

Affected Software

cloud foundry, cloud foundry elastic runtime, cloud foundry uaa, cloud foundry uaa-release
Vulnerable Versions:
0, 1.6.0, 1.7.0

Timeline

Official Publish: April 24th, 2017
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.