Description
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and potential escalation of privileges.
CVSS Metrics
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Vector
- network
- Complexity
- low
- Privileges
- low
- User Action
- none
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- high
- Availability
- high
- Weaknesses
- NVD-CWE-noinfo
Metadata
- Primary Vendor
- PIVOTAL_SOFTWARE
- Published
- 6/13/2017
- Last Modified
- 4/20/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
pivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtimepivotal_software : cloud_foundry_elastic_runtime
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.