Loading
Generated remediation guidance and an executive summary. No account required.
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
Use CWE-640, Cloudfoundry vendor hub and Cf-Release product page to widen CVE-2015-5172 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-5171, CVE-2016-6658 and CVE-2018-1195 for nearby disclosures in the same product family.