{"id":"CVE-2016-0927","details":"Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","modified":"2026-07-08T05:45:30.546636601Z","published":"2016-09-18T02:59:07.947Z","database_specific":{"unresolved_ranges":[{"vendor_product":"pivotal_software:cloud_foundry_elastic_runtime","cpes":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.6.0"},{"last_affected":"1.6.0"},{"introduced":"1.6.6"},{"last_affected":"1.6.6"},{"introduced":"1.6.6"},{"last_affected":"1.6.6"},{"introduced":"1.6.7"},{"last_affected":"1.6.7"},{"introduced":"1.6.7"},{"last_affected":"1.6.7"},{"introduced":"1.6.8"},{"last_affected":"1.6.8"},{"introduced":"1.6.8"},{"last_affected":"1.6.8"},{"introduced":"1.6.9"},{"last_affected":"1.6.9"},{"introduced":"1.6.9"},{"last_affected":"1.6.9"},{"introduced":"1.6.10"},{"last_affected":"1.6.10"},{"introduced":"1.6.10"},{"last_affected":"1.6.10"},{"introduced":"1.6.11"},{"last_affected":"1.6.11"},{"introduced":"1.6.11"},{"last_affected":"1.6.11"},{"introduced":"1.6.12"},{"last_affected":"1.6.12"},{"introduced":"1.6.12"},{"last_affected":"1.6.12"},{"introduced":"1.6.13"},{"last_affected":"1.6.13"},{"introduced":"1.6.13"},{"last_affected":"1.6.13"},{"introduced":"1.6.14"},{"last_affected":"1.6.14"},{"introduced":"1.6.14"},{"last_affected":"1.6.14"},{"introduced":"1.6.15"},{"last_affected":"1.6.15"},{"introduced":"1.6.15"},{"last_affected":"1.6.15"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-0927"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa","events":[{"introduced":"ae59bf11fec166fd075b1dbead2ae16effa57e3f"},{"last_affected":"cde7ba5da9b64cb45bd64c61c6fb2899bbc3e0f2"}],"database_specific":{"cpe":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.6.0"},{"last_affected":"1.6.0"},{"introduced":"1.6.1"},{"last_affected":"1.6.1"},{"introduced":"1.6.2"},{"last_affected":"1.6.2"},{"introduced":"1.6.3"},{"last_affected":"1.6.3"},{"introduced":"1.6.4"},{"last_affected":"1.6.4"},{"introduced":"1.6.5"},{"last_affected":"1.6.5"}],"source":"CPE_STRING"}}],"versions":["1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0927.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}