CVE-2016-5016

Source
https://cve.org/CVERecord?id=CVE-2016-5016
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5016.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-5016
Aliases
Published
2017-04-24T19:59:00.253Z
Modified
2026-07-08T05:48:59.018351477Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "239"
                }
            ],
            "cpes": [
                "cpe:2.3:a:pivotal_software:cloud_foundry:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE",
            "vendor_product": "pivotal_software:cloud_foundry"
        },
        {
            "extracted_events": [
                {
                    "introduced": "1.6.0"
                },
                {
                    "fixed": "1.6.35"
                },
                {
                    "introduced": "1.6.0"
                },
                {
                    "fixed": "1.6.35"
                },
                {
                    "introduced": "1.7.0"
                },
                {
                    "fixed": "1.7.13"
                },
                {
                    "introduced": "1.7.0"
                },
                {
                    "fixed": "1.7.13"
                }
            ],
            "cpes": [
                "cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*"
            ],
            "source": "CPE_RANGE",
            "vendor_product": "pivotal_software:cloud_foundry_elastic_runtime"
        }
    ]
}
References

Affected packages

Git
github.com/cloudfoundry-attic/cf-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry-attic/cf-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
-
list
log
scotty_09012012
v100
v102
v103
v104
v105
v109
v119
v132
v133
v134
v135
v136
v137
v140
v143
v156
v157
v161
v170
v183
v205
v99
works-for-us
rc145.*
rc145.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5016.json"
github.com/cloudfoundry/uaa

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.4.1"
        }
    ],
    "cpe": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.1
1.0.3
1.1
1.1.1
1.1.2
1.10
1.11
1.2.0
1.2.6
1.4.0
1.4.1
1.4.2
1.4.3
1.4.5
1.4.6
1.4.7
1.5.0
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.0
1.6.1
1.6.2
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.2.4.1
2.2.5
2.2.6
2.3.0
2.3.1
2.3.1.1
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.0.1
2.7.0.2
2.7.0.3
2.7.1
2.7.2
2.7.3
2.7.4
2.7.4.1
2.7.4.2
2.7.4.3
2.7.4.4
2.7.4.5
3.*
3.0.0
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.0.1
3.3.0.2
3.4.0
3.4.1
Other
lenient_hybrid_flow
travis-success-1475
travis-success-1478
travis-success-1497

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5016.json"
github.com/cloudfoundry/uaa-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "12.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

Other
v10
v11
v12
v2
v3
v6
v7
v8
v9
v11.*
v11.1
v11.2
v12.*
v12.1
v12.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-5016.json"