Loading
Generated remediation guidance and an executive summary. No account required.
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
Use CWE-284, Pivotal Software vendor hub and Cloud Foundry Uaa product page to widen CVE-2019-3794 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-15761, CVE-2015-5172 and CVE-2015-5171 for nearby disclosures in the same product family.