PT-2017-8487 · Bosh · Bosh Director Vm Stemcell
Published
2017-05-25
·
Updated
2017-10-02
·
CVE-2016-4435
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BOSH Director VM stemcell versions prior to 3232.6
BOSH Director VM stemcell versions prior to 3146.13
Description
The issue allows unauthenticated clients to potentially read or write blobs or cause a denial of service attack on the Director VM by guessing or finding a URL matching an existing GUID, affecting an endpoint of the Agent running on the BOSH Director VM.
Recommendations
For stemcell versions prior to 3232.6, update to version 3232.6 or later to resolve the issue.
For stemcell versions prior to 3146.13, update to version 3146.13 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh Director Vm Stemcell