Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-3085


Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass authentication and access the user interface via vectors related to the SAML plugin.


Published

2016-06-10T15:59:02.360

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-254
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache cloudstack 4.7.0 Yes
Application apache cloudstack 4.5.1 Yes
Application apache cloudstack 4.5.2 Yes
Application apache cloudstack 4.6.0 Yes
Application apache cloudstack 4.6.1 Yes
Application apache cloudstack 4.6.2 Yes
Application apache cloudstack 4.8 Yes

References