CVE CVE-2018-15795 Mappings

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
CVE-2018-15795 CredHub Service Broker primary_impact T1078 Valid Accounts
CVE-2018-15795 CredHub Service Broker exploitation_technique T1110 Brute Force