CVE-2016-0732: Cloudfoundry Cf-Release

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.

Affected products

  • Cloudfoundry Cf-Release: from 208, up to and including 229
  • Cloudfoundry Uaa-Release: version 2 only; version 3 only; version 4 only
  • Cloudfoundry User Account And Authentication: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.1.0 only; version 2.2.0 only; …
  • Pivotal Elastic Runtime: version 1.6.0 only; version 1.6.1 only; version 1.6.2 only; version 1.6.3 only; version 1.6.4 only; version 1.6.5 only; …

Published 2017-09-07. Last modified 2026-06-17.