UAA Release (OSS)
Cloud Foundry- Product type
- Other
- Catalog vulnerabilities
- 10
Severity across 10 analyzed records
Verify to analyze this security profile
en
Severity across 10 analyzed records
Verify to analyze this security profile
As of 09/16/2026, within CyStack's analyzed data, UAA Release (OSS) has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of UAA Release (OSS) and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2019-11279Privilege Escalation via Scope Manipulation in UAA | Exploitation statusNot confirmed | FixNot confirmed | Published09/26/2019 | SeverityHigh |
CVE-2019-11278Privilege Escalation via Blind SCIM Injection in UAA | Exploitation statusNot confirmed | FixNot confirmed | Published09/26/2019 | SeverityHigh |
CVE-2019-11274UAA SCIM Filter XSS | Exploitation statusNot confirmed | FixNot confirmed | Published08/09/2019 | SeverityMedium |
CVE-2019-11270UAA clients.write vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Published08/05/2019 | SeverityHigh |
CVE-2019-3794UAA - Login app subject to clickjacking attack | Exploitation statusNot confirmed | FixYes | Published07/18/2019 | SeverityMedium |
CVE-2019-11268UAA SQL Identity Zone Vulnerability | Exploitation statusNot confirmed | FixNot confirmed | Published07/11/2019 | SeverityMedium |
CVE-2019-3787UAA defaults email address to an insecure domain | Exploitation statusNot confirmed | FixYes | Published06/19/2019 | SeverityHigh |
CVE-2019-3801Java Projects using HTTP to fetch dependencies | Exploitation statusNot confirmed | FixYes | Published04/25/2019 | SeverityHigh |
CVE-2019-3788UAA redirect-uri allows wildcard in the subdomain | Exploitation statusNot confirmed | FixYes | Published04/25/2019 | SeverityHigh |
CVE-2019-3775UAA allows users to modify their own email address | Exploitation statusNot confirmed | FixYes | Published03/07/2019 | SeverityHigh |