PT-2017-10381 · Pivotal · Pivotal Gemfire For Pcf
Publicado
2017-01-06
·
Atualizado
2017-01-11
·
CVE-2016-9885
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pivotal GemFire for PCF versions prior to 1.6.5
Pivotal GemFire for PCF versions prior to 1.7.1
Description
An issue was discovered where the gfsh endpoint is unauthenticated and publicly accessible. This allows an attacker to run any command available on gfsh, potentially causing denial of service, lost confidentiality of data, privilege escalation, or eavesdropping on communications between the gorouter and the cluster. The communications from the gorouter to GemFire clusters are unencrypted because HTTPS communications are terminated at the gorouter.
Recommendations
For Pivotal GemFire for PCF versions prior to 1.6.5, update to version 1.6.5 or later.
For Pivotal GemFire for PCF versions prior to 1.7.1, update to version 1.7.1 or later.
Correção
DoS
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pivotal Gemfire For Pcf