PT-2016-4483 · Vmware+1 · Vcloud+2
Publicado
2016-09-18
·
Atualizado
2016-11-28
·
CVE-2016-0930
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pivotal Cloud Foundry (PCF) Ops Manager versions 1.6.0 through 1.6.18
Pivotal Cloud Foundry (PCF) Ops Manager versions 1.7.0 through 1.7.9
Description
The issue allows remote attackers to obtain SSH access to compilation VMs by connecting within an installation-time period during which these VMs exist, due to a default password. This is possible when vCloud or vSphere is used.
Recommendations
For Pivotal Cloud Foundry (PCF) Ops Manager versions 1.6.0 through 1.6.18, update to version 1.6.19 or later.
For Pivotal Cloud Foundry (PCF) Ops Manager versions 1.7.0 through 1.7.9, update to version 1.7.10 or later.
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pivotal Cloud Foundry (Pcf) Ops Manager
Vcloud
Vsphere