Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-11278

CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.3%
CVSS Severity
CVSS v3 Score 8.7
CVSS v2 Score 6.5
Products affected by CVE-2019-11278


Contact Us

Shodan ® - All rights reserved