Vulnerability Details CVE-2019-3775
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.2%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 4.0
Products affected by CVE-2019-3775
-
cpe:2.3:a:cloudfoundry:uaa_release:10.0
-
cpe:2.3:a:cloudfoundry:uaa_release:11.0
-
cpe:2.3:a:cloudfoundry:uaa_release:11.1
-
cpe:2.3:a:cloudfoundry:uaa_release:11.2
-
cpe:2.3:a:cloudfoundry:uaa_release:11.3
-
cpe:2.3:a:cloudfoundry:uaa_release:11.4
-
cpe:2.3:a:cloudfoundry:uaa_release:11.5
-
cpe:2.3:a:cloudfoundry:uaa_release:11.7
-
cpe:2.3:a:cloudfoundry:uaa_release:12.0
-
cpe:2.3:a:cloudfoundry:uaa_release:12.1
-
cpe:2.3:a:cloudfoundry:uaa_release:12.2
-
cpe:2.3:a:cloudfoundry:uaa_release:12.3
-
cpe:2.3:a:cloudfoundry:uaa_release:12.4
-
cpe:2.3:a:cloudfoundry:uaa_release:12.5
-
cpe:2.3:a:cloudfoundry:uaa_release:12.6
-
cpe:2.3:a:cloudfoundry:uaa_release:13.0
-
cpe:2.3:a:cloudfoundry:uaa_release:13.1
-
cpe:2.3:a:cloudfoundry:uaa_release:13.10
-
cpe:2.3:a:cloudfoundry:uaa_release:13.11
-
cpe:2.3:a:cloudfoundry:uaa_release:13.12
-
cpe:2.3:a:cloudfoundry:uaa_release:13.13
-
cpe:2.3:a:cloudfoundry:uaa_release:13.14
-
cpe:2.3:a:cloudfoundry:uaa_release:13.15
-
cpe:2.3:a:cloudfoundry:uaa_release:13.16
-
cpe:2.3:a:cloudfoundry:uaa_release:13.17
-
cpe:2.3:a:cloudfoundry:uaa_release:13.18
-
cpe:2.3:a:cloudfoundry:uaa_release:13.2
-
cpe:2.3:a:cloudfoundry:uaa_release:13.3
-
cpe:2.3:a:cloudfoundry:uaa_release:13.4
-
cpe:2.3:a:cloudfoundry:uaa_release:13.5
-
cpe:2.3:a:cloudfoundry:uaa_release:13.6
-
cpe:2.3:a:cloudfoundry:uaa_release:13.7
-
cpe:2.3:a:cloudfoundry:uaa_release:13.8
-
cpe:2.3:a:cloudfoundry:uaa_release:13.9
-
cpe:2.3:a:cloudfoundry:uaa_release:14.0
-
cpe:2.3:a:cloudfoundry:uaa_release:15.0
-
cpe:2.3:a:cloudfoundry:uaa_release:16.0
-
cpe:2.3:a:cloudfoundry:uaa_release:17.0
-
cpe:2.3:a:cloudfoundry:uaa_release:18.0
-
cpe:2.3:a:cloudfoundry:uaa_release:19.0
-
cpe:2.3:a:cloudfoundry:uaa_release:2.0
-
cpe:2.3:a:cloudfoundry:uaa_release:20.0
-
cpe:2.3:a:cloudfoundry:uaa_release:21.0
-
cpe:2.3:a:cloudfoundry:uaa_release:22.0
-
cpe:2.3:a:cloudfoundry:uaa_release:23.0
-
cpe:2.3:a:cloudfoundry:uaa_release:24.0
-
cpe:2.3:a:cloudfoundry:uaa_release:24.1
-
cpe:2.3:a:cloudfoundry:uaa_release:24.10
-
cpe:2.3:a:cloudfoundry:uaa_release:24.11
-
cpe:2.3:a:cloudfoundry:uaa_release:24.12
-
cpe:2.3:a:cloudfoundry:uaa_release:24.13
-
cpe:2.3:a:cloudfoundry:uaa_release:24.14
-
cpe:2.3:a:cloudfoundry:uaa_release:24.2
-
cpe:2.3:a:cloudfoundry:uaa_release:24.3
-
cpe:2.3:a:cloudfoundry:uaa_release:24.4
-
cpe:2.3:a:cloudfoundry:uaa_release:24.5
-
cpe:2.3:a:cloudfoundry:uaa_release:24.6
-
cpe:2.3:a:cloudfoundry:uaa_release:24.7
-
cpe:2.3:a:cloudfoundry:uaa_release:24.8
-
cpe:2.3:a:cloudfoundry:uaa_release:24.9
-
cpe:2.3:a:cloudfoundry:uaa_release:25.0
-
cpe:2.3:a:cloudfoundry:uaa_release:26.0
-
cpe:2.3:a:cloudfoundry:uaa_release:27.0
-
cpe:2.3:a:cloudfoundry:uaa_release:28.0
-
cpe:2.3:a:cloudfoundry:uaa_release:29.0
-
cpe:2.3:a:cloudfoundry:uaa_release:3.0
-
cpe:2.3:a:cloudfoundry:uaa_release:30.0
-
cpe:2.3:a:cloudfoundry:uaa_release:30.1
-
cpe:2.3:a:cloudfoundry:uaa_release:30.2
-
cpe:2.3:a:cloudfoundry:uaa_release:30.3
-
cpe:2.3:a:cloudfoundry:uaa_release:30.4
-
cpe:2.3:a:cloudfoundry:uaa_release:30.5
-
cpe:2.3:a:cloudfoundry:uaa_release:30.6
-
cpe:2.3:a:cloudfoundry:uaa_release:30.7
-
cpe:2.3:a:cloudfoundry:uaa_release:30.8
-
cpe:2.3:a:cloudfoundry:uaa_release:30.9
-
cpe:2.3:a:cloudfoundry:uaa_release:31.0
-
cpe:2.3:a:cloudfoundry:uaa_release:32.0
-
cpe:2.3:a:cloudfoundry:uaa_release:33.0
-
cpe:2.3:a:cloudfoundry:uaa_release:34.0
-
cpe:2.3:a:cloudfoundry:uaa_release:34.1
-
cpe:2.3:a:cloudfoundry:uaa_release:34.2
-
cpe:2.3:a:cloudfoundry:uaa_release:34.3
-
cpe:2.3:a:cloudfoundry:uaa_release:35.0
-
cpe:2.3:a:cloudfoundry:uaa_release:36.0
-
cpe:2.3:a:cloudfoundry:uaa_release:37.0
-
cpe:2.3:a:cloudfoundry:uaa_release:38.0
-
cpe:2.3:a:cloudfoundry:uaa_release:39.0
-
cpe:2.3:a:cloudfoundry:uaa_release:4.0
-
cpe:2.3:a:cloudfoundry:uaa_release:40.0
-
cpe:2.3:a:cloudfoundry:uaa_release:41.0
-
cpe:2.3:a:cloudfoundry:uaa_release:41.1
-
cpe:2.3:a:cloudfoundry:uaa_release:43.0
-
cpe:2.3:a:cloudfoundry:uaa_release:44.0
-
cpe:2.3:a:cloudfoundry:uaa_release:45.0
-
cpe:2.3:a:cloudfoundry:uaa_release:45.1
-
cpe:2.3:a:cloudfoundry:uaa_release:45.10
-
cpe:2.3:a:cloudfoundry:uaa_release:45.11
-
cpe:2.3:a:cloudfoundry:uaa_release:45.2
-
cpe:2.3:a:cloudfoundry:uaa_release:45.3
-
cpe:2.3:a:cloudfoundry:uaa_release:45.4
-
cpe:2.3:a:cloudfoundry:uaa_release:45.5
-
cpe:2.3:a:cloudfoundry:uaa_release:45.6
-
cpe:2.3:a:cloudfoundry:uaa_release:45.7
-
cpe:2.3:a:cloudfoundry:uaa_release:45.8
-
cpe:2.3:a:cloudfoundry:uaa_release:45.9
-
cpe:2.3:a:cloudfoundry:uaa_release:48.0
-
cpe:2.3:a:cloudfoundry:uaa_release:5.0
-
cpe:2.3:a:cloudfoundry:uaa_release:50.0
-
cpe:2.3:a:cloudfoundry:uaa_release:51.0
-
cpe:2.3:a:cloudfoundry:uaa_release:52.0
-
cpe:2.3:a:cloudfoundry:uaa_release:52.1
-
cpe:2.3:a:cloudfoundry:uaa_release:52.10
-
cpe:2.3:a:cloudfoundry:uaa_release:52.2
-
cpe:2.3:a:cloudfoundry:uaa_release:52.4
-
cpe:2.3:a:cloudfoundry:uaa_release:52.5
-
cpe:2.3:a:cloudfoundry:uaa_release:52.6
-
cpe:2.3:a:cloudfoundry:uaa_release:52.7
-
cpe:2.3:a:cloudfoundry:uaa_release:52.8
-
cpe:2.3:a:cloudfoundry:uaa_release:52.9
-
cpe:2.3:a:cloudfoundry:uaa_release:53.0
-
cpe:2.3:a:cloudfoundry:uaa_release:53.1
-
cpe:2.3:a:cloudfoundry:uaa_release:53.2
-
cpe:2.3:a:cloudfoundry:uaa_release:53.3
-
cpe:2.3:a:cloudfoundry:uaa_release:54.0
-
cpe:2.3:a:cloudfoundry:uaa_release:55.0
-
cpe:2.3:a:cloudfoundry:uaa_release:55.1
-
cpe:2.3:a:cloudfoundry:uaa_release:55.2
-
cpe:2.3:a:cloudfoundry:uaa_release:56.0
-
cpe:2.3:a:cloudfoundry:uaa_release:57.0
-
cpe:2.3:a:cloudfoundry:uaa_release:57.1
-
cpe:2.3:a:cloudfoundry:uaa_release:57.2
-
cpe:2.3:a:cloudfoundry:uaa_release:57.3
-
cpe:2.3:a:cloudfoundry:uaa_release:57.4
-
cpe:2.3:a:cloudfoundry:uaa_release:58.0
-
cpe:2.3:a:cloudfoundry:uaa_release:58.1
-
cpe:2.3:a:cloudfoundry:uaa_release:59.0
-
cpe:2.3:a:cloudfoundry:uaa_release:6.0
-
cpe:2.3:a:cloudfoundry:uaa_release:60.0
-
cpe:2.3:a:cloudfoundry:uaa_release:60.2
-
cpe:2.3:a:cloudfoundry:uaa_release:61.0
-
cpe:2.3:a:cloudfoundry:uaa_release:62.0
-
cpe:2.3:a:cloudfoundry:uaa_release:63.0
-
cpe:2.3:a:cloudfoundry:uaa_release:64.0
-
cpe:2.3:a:cloudfoundry:uaa_release:66.0
-
cpe:2.3:a:cloudfoundry:uaa_release:67.0
-
cpe:2.3:a:cloudfoundry:uaa_release:68.0
-
cpe:2.3:a:cloudfoundry:uaa_release:69.0
-
cpe:2.3:a:cloudfoundry:uaa_release:7.0
-
cpe:2.3:a:cloudfoundry:uaa_release:8.0
-
cpe:2.3:a:cloudfoundry:uaa_release:9.0