{"id":"CVE-2016-3084","details":"The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.","aliases":["GHSA-fm5c-2rwc-887w"],"modified":"2026-08-27T03:45:11.676876330Z","published":"2017-05-25T17:29:00.630Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"pivotal_software:cloud_foundry_elastic_runtime","cpes":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"1.7.1"}]}]},"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-3084"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry-attic/cf-release","events":[{"introduced":"0"},{"last_affected":"9a550e9dbce3fbd779263dff5f5458be8ce88c79"}],"database_specific":{"cpe":"cpe:2.3:a:pivotal_software:cloud_foundry:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"236"}],"source":"CPE_RANGE"}}],"versions":["v236","v205","v183","v170","v161","v157","v156","rc145.0","v143","works-for-us","v140","v137","v136","v135","v134","v133","v132","scotty_09012012","v119","v109","v105","v104","v103","v102","v100","v99","-","log","list"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3084.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa","events":[{"introduced":"0"},{"last_affected":"36efbc0bf6186a4abaf51c04e55cdb2d5e15091b"},{"last_affected":"85fbe8ee080c50a86ac2f90fcdc705e3db6e82eb"}],"database_specific":{"cpe":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.7.1"},{"last_affected":"3.3.0"}],"source":"CPE_RANGE"}}],"versions":["3.3.0","3.2.1","3.2.0","3.1.0","3.0.1","3.0.0","2.7.3","2.7.2","2.7.1","2.7.0.3","2.7.0.2","2.7.0.1","2.7.0","2.6.2","2.6.1","2.6.0","2.5.2","2.5.1","2.5.0","2.4.1","2.2.5","2.4.0","2.3.1.1","2.3.1","2.3.0","2.2.6","2.2.4.1","2.1.0","2.0.3","2.0.2","2.0.1","2.0.0","lenient_hybrid_flow","1.11","1.10","1.9.1","1.9.0","1.8.3","1.8.2","1.8.1","1.7.2","1.7.1","1.7.0","1.6.5","1.6.4","1.6.0","1.5.4.1","1.5.4","1.5.3","1.5.2.1","1.5.2","1.5.0","1.4.7","1.4.6","1.4.5","1.4.3","1.4.2","1.4.1","1.4.0","1.2.6","1.2.0","1.1.2","1.1.1","1.1","1.0.3","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3084.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa-release","events":[{"introduced":"0"},{"last_affected":"ba330dcf9a5f864af59d0904449dbf1b2954b3b4"}],"database_specific":{"cpe":"cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"10"}],"source":"CPE_RANGE"}}],"versions":["v10","v9","v8","v7","v6","v3","v2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-3084.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}