LiveActive security incident?Get immediate response
CVE Record

CVE-2015-3189: With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier an...

With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw affects older Cloud Foundry and Pivotal Cloud Foundry deployments using UAA's internal user store. Password reset links could remain valid after a user changes their email address, creating a stale account-recovery path. Deployments using SAML or LDAP authentication are stated as not affected.

Executive priority

Treat this as a targeted legacy-platform risk. It is not supported by evidence of active exploitation in the bundle, but affected internal-user-store deployments should be upgraded or validated because stale reset links can weaken account recovery controls.

Technical view

CVE-2015-3189 concerns UAA password reset link invalidation. In affected versions, changing the account email address does not expire previously issued reset links. The source bundle names cf-release v208 or earlier, UAA Standalone 2.2.5 or earlier, and Pivotal Cloud Foundry Runtime 1.4.5 or earlier.

Likely exposure

Exposure is limited to affected Cloud Foundry or Pivotal Cloud Foundry versions using the UAA internal user store. SAML-integrated or LDAP-integrated authentication deployments are explicitly described as not affected.

Exploitation context

The bundle does not cite active exploitation, and the CVE is not marked KEV. Practical risk depends on whether an attacker can obtain or use an old password reset link for an account in an affected deployment.

Researcher notes

Key scope constraints are authentication mode and version. The provided data lacks CVSS, CWE, exploit maturity, and detailed fix text. Avoid assuming exposure for SAML or LDAP deployments, which the CVE description excludes.

Mitigation direction

  • Inventory Cloud Foundry Runtime, UAA Standalone, and Pivotal Cloud Foundry Runtime versions.
  • Confirm whether UAA internal user store authentication is enabled.
  • Move off affected versions after confirming vendor upgrade guidance.
  • Consult the Pivotal advisory for fixed versions or supported mitigation details.
  • Prefer SAML or LDAP where already supported and appropriate.

Validation and detection

  • Check whether cf-release is v208 or earlier.
  • Check whether UAA Standalone is 2.2.5 or earlier.
  • Check whether Pivotal Cloud Foundry Runtime is 1.4.5 or earlier.
  • Verify authentication mode is not UAA internal user store.
  • Review account recovery logs for unusual password reset activity.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2015-3189 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
PivotalCloud FoundryRuntime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier, Runtime 1.4.5 or earlierListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.