Session Information Vulnerability in Multi-Zone UAA by Cloud Foundry
CVE-2025-22216

5.4MEDIUM

Key Information:

Vendor
CVE Published:
31 January 2025

What is CVE-2025-22216?

The affected UAA configuration with multiple identity zones fails to validate session information adequately. This security flaw allows a user authenticated against a corporate Identity Provider (IDP) to reuse their jsessionid, potentially gaining unauthorized access to other zones. This misconfiguration can lead to significant security implications, as it enables the compromise of sensitive data across different identity zones.

Affected Version(s)

Cloud Foundry UAA any 77.20.X

Cloud Foundry UAA any 77.20.X < 77.20.2

Cloud Foundry UAA any 77.2X.0 < 77.25.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.