PT-2017-8487 · Bosh · Bosh Director Vm Stemcell

Publicado

2017-05-25

·

Atualizado

2017-10-02

·

CVE-2016-4435

CVSS v3.1

9.0

Crítica

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BOSH Director VM stemcell versions prior to 3232.6 BOSH Director VM stemcell versions prior to 3146.13
Description The issue allows unauthenticated clients to potentially read or write blobs or cause a denial of service attack on the Director VM by guessing or finding a URL matching an existing GUID, affecting an endpoint of the Agent running on the BOSH Director VM.
Recommendations For stemcell versions prior to 3232.6, update to version 3232.6 or later to resolve the issue. For stemcell versions prior to 3146.13, update to version 3146.13 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4435

Produtos afetados

Bosh Director Vm Stemcell