PT-2018-5118 · Pivotal · Gemfire Broker For Cloud Foundry
Published
2018-03-16
·
Updated
2018-04-10
·
CVE-2016-9880
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GemFire broker for Cloud Foundry versions 1.6.x through 1.6.4
GemFire broker for Cloud Foundry versions 1.7.x through 1.7.0
Description
The issue concerns multiple API endpoints that do not require authentication, potentially allowing unauthorized access to the cluster managed by the broker.
Recommendations
For GemFire broker for Cloud Foundry versions 1.6.x through 1.6.4, update to version 1.6.5 or later.
For GemFire broker for Cloud Foundry versions 1.7.x through 1.7.0, update to version 1.7.1 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gemfire Broker For Cloud Foundry