CVE-2016-9877
Summary
| CVE | CVE-2016-9877 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-12-29 09:59:00 UTC |
| Updated | 2022-03-17 14:02:00 UTC |
| Description | An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Rabbitmq | 1.5.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.10 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.11 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.12 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.13 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.14 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.15 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.17 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.18 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.8 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.9 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.10 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.8 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.9 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.10 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.11 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.12 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.13 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.14 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.15 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.17 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.18 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.8 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.5.9 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.10 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.8 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.6.9 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 1.7.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.0.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.1.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.2.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.3.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.4.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.5 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.6 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.5.7 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.0 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.1 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.2 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.3 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.4 | All | All | All |
| Application | Pivotal Software | Rabbitmq | 3.6.5 | All | All | All |
| Application | Vmware | Rabbitmq | 3.0.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.0.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.0.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.0.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.0.4 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.4 | All | All | All |
| Application | Vmware | Rabbitmq | 3.1.5 | All | All | All |
| Application | Vmware | Rabbitmq | 3.2.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.2.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.2.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.2.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.2.4 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.4 | All | All | All |
| Application | Vmware | Rabbitmq | 3.3.5 | All | All | All |
| Application | Vmware | Rabbitmq | 3.4.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.4.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.4.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.4.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.4.4 | All | All | All |
| Application | Vmware | Rabbitmq | 3.5.0 | All | All | All |
| Application | Vmware | Rabbitmq | 3.5.1 | All | All | All |
| Application | Vmware | Rabbitmq | 3.5.2 | All | All | All |
| Application | Vmware | Rabbitmq | 3.5.3 | All | All | All |
| Application | Vmware | Rabbitmq | 3.5.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | CONFIRM | support.hpe.com | |
| Debian -- Security Information -- DSA-3761-1 rabbitmq-server | DEBIAN | www.debian.org | |
| CVE-2016-9877 RabbitMQ authentication vulnerability | Security | Pivotal | CONFIRM | pivotal.io | Mitigation, Vendor Advisory |
| Pivotal RabbitMQ Products CVE-2016-9877 Authentication Bypass Vulnerability | BID | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690144 Free Berkeley Software Distribution (FreeBSD) Security Update for rabbitmq (b1aa54ae-74cb-42a0-b462-cbb6831c5c50)