PT-2016-4442 · Pivotal · Pivotal Cloud Foundry (Pcf) Ops Manager

Published

2016-09-18

·

Updated

2016-10-03

·

CVE-2016-0883

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pivotal Cloud Foundry (PCF) Ops Manager versions prior to 1.5.14 Pivotal Cloud Foundry (PCF) Ops Manager versions 1.6.x prior to 1.6.9
Description The issue allows remote attackers to bypass session authentication by leveraging knowledge of the cookie-encryption key from another installation, as the same key is used across different customers' installations.
Recommendations For versions prior to 1.5.14, update to version 1.5.14 or later. For versions 1.6.x prior to 1.6.9, update to version 1.6.9 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0883

Affected Products

Pivotal Cloud Foundry (Pcf) Ops Manager