CVE-2015-3189

low
Published 2017-05-25 · Modified 2024-02-28
CVSS v3
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2
4.3
VIR risk
3.7

Description

Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password

Predictions

Exploit likelihood
47%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security_alert@emc.com — https://pivotal.io/security/cve-2015-3189

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.cloudfoundry.identity:cloudfoundry-identity-server<2.2.52.2.5

Application impact

VendorProductVersionsFixed
cloudfoundrycf-release{"endIncluding":"208"}
pivotal_softwarecloud_foundry_elastic_runtime{"endIncluding":"1.4.5"}
pivotal_softwarecloud_foundry_uaa{"endIncluding":"2.2.5"}

References

CWEs

CWE-640

Verify integrity in audit chain (admin only). AS-IS.