CVE-2016-5016: Pivotal Software Cloud Foundry

Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

Affected products

  • Pivotal Software Cloud Foundry: up to and including 239
  • Pivotal Software Cloud Foundry Elastic Runtime: from 1.6.0, before 1.6.35 (fixed in 1.6.35); from 1.7.0, before 1.7.13 (fixed in 1.7.13)
  • Pivotal Software Cloud Foundry Uaa: up to and including 3.4.1
  • Pivotal Software Cloud Foundry Uaa-Release: up to and including 12.2

Published 2017-04-24. Last modified 2026-06-17.