Uaa
This hub aggregates every CVE we track for Uaa, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
3
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM3CRITICAL3LOW1
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
1
1
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Uaa.
- CVE-2026-47840LDAP StartTLS unconditionally disables hostname verification7.5
- CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass9.0
- CVE-2026-22723UAA User Token Revocation logic error6.5
- CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure3.0
- CVE-2022-31197SQL Injection in ResultSet.refreshRow() with malicious column names in pgjdbc7.1
- CVE-2020-5402UAA fails to check the state parameter when authenticating with external IDPs8.8
- CVE-2018-15761UAA Privilege Escalation9.9
- CVE-2018-11082Cloud Foundry UAA MFA does not prevent brute force of MFA code6.6
- CVE-2018-1190An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions ...6.1
- CVE-2015-5171The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified ...9.8
Product normalization is registry-driven with AI assist and human review. How it works