CVE-2016-9885
Summary
| CVE | CVE-2016-9885 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-06 22:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticated and publicly accessible. Because HTTPS communications are terminated at the gorouter, communications from the gorouter to GemFire clusters are unencrypted. An attacker could run any command available on gfsh and could cause denial of service, lost confidentiality of data, escalate privileges, or eavesdrop on other communications between the gorouter and the cluster. |
Risk And Classification
Primary CVSS: v3.0 9.8 CRITICAL from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.005410000 probability, percentile 0.677240000 (date 2026-05-11)
Problem Types: CWE-200 | CWE-254 | gfsh exposed over go router for GemFire for PCF
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.6.0.0 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.6.1 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.6.2 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.6.3.0 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.6.4.0 | All | All | All |
| Application | Pivotal Software | Gemfire For Pivotal Cloud Foundry | 1.7.0.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | GemFire For PCF 1.6.x Versions Prior To 1.6.5 And 1.7.x Versions Prior To 1.7.1 | affected GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pivotal GemFire for PCF CVE-2016-9885 Remote Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2016-9885 gfsh exposed over go router for GemFire for PCF | Security | Pivotal | af854a3a-2127-422b-91ae-364da2661108 | pivotal.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.