CVE-2016-9880
Summary
| CVE | CVE-2016-9880 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-16 20:29:00 UTC |
| Updated | 2018-04-10 13:38:00 UTC |
| Description | The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | All | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.7.0 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | All | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pivotal GemFire for PCF CVE-2016-9880 Unauthenticated Access Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE-2016-9880 Unauthenticated access to GemFire for PCF broker endpoints | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.