{"api_version":"1","generated_at":"2026-07-23T07:59:36+00:00","cve":"CVE-2016-9880","urls":{"html":"https://cve.report/CVE-2016-9880","api":"https://cve.report/api/cve/CVE-2016-9880.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-9880","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-9880"},"summary":{"title":"CVE-2016-9880","description":"The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.","state":"PUBLIC","assigner":"security_alert@emc.com","published_at":"2018-03-16 20:29:00","updated_at":"2018-04-10 13:38:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/96146","name":"96146","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Pivotal GemFire for PCF CVE-2016-9880 Unauthenticated Access Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://pivotal.io/security/cve-2016-9880","name":"https://pivotal.io/security/cve-2016-9880","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"CVE-2016-9880 Unauthenticated access to GemFire for PCF broker endpoints | Security | Pivotal","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-9880","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-9880","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"9880","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"gemfire_for_pivotal_cloud_foundry","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"9880","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"gemfire_for_pivotal_cloud_foundry","cpe6":"1.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"9880","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"gemfire_for_pivotal_cloud_foundry","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"9880","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"gemfire_for_pivotal_cloud_foundry","cpe6":"1.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","DATE_PUBLIC":"2017-02-09T00:00:00","ID":"CVE-2016-9880","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"GemFire broker for Cloud Foundry","version":{"version_data":[{"version_value":"1.6.x versions prior to 1.6.5"},{"version_value":"1.7.x versions prior to 1.7.1"}]}}]},"vendor_name":"Dell EMC"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Unauthenticated access"}]}]},"references":{"reference_data":[{"name":"https://pivotal.io/security/cve-2016-9880","refsource":"CONFIRM","url":"https://pivotal.io/security/cve-2016-9880"},{"name":"96146","refsource":"BID","url":"http://www.securityfocus.com/bid/96146"}]}},"nvd":{"publishedDate":"2018-03-16 20:29:00","lastModifiedDate":"2018-04-10 13:38:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pivotal_software:gemfire_for_pivotal_cloud_foundry:*:*:*:*:*:*:*:*","versionStartIncluding":"1.6.0","versionEndExcluding":"1.6.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pivotal_software:gemfire_for_pivotal_cloud_foundry:1.7.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"9880","Ordinal":"99494","Title":"CVE-2016-9880","CVE":"CVE-2016-9880","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"9880","Ordinal":"1","NoteData":"The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"9880","Ordinal":"2","NoteData":"2018-03-16","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"9880","Ordinal":"3","NoteData":"2018-03-17","Type":"Other","Title":"Modified"}]}}}