Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue.
Conclusion & alert: CVE-2016-0708 is rated Moderate Risk (50.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.56%). Core evidence: EPSS rose +1.34% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.22% | 1.56% | +1.34% |
| 2 | 2025-03-30 | 0.42% | 0.22% | -0.20% |
| 3 | 2025-03-29 | — | 0.42% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cloudfoundry | cf-release | >= 166, <= 227 | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* |
| cloudfoundry | java_buildpack | >= 2.0, <= 3.4 | cpe:2.3:a:cloudfoundry:java_buildpack:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2016-0708/ | Mitigation Vendor Advisory |