PT-2018-5118 · Pivotal · Gemfire Broker For Cloud Foundry

Published

2018-03-16

·

Updated

2018-04-10

·

CVE-2016-9880

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GemFire broker for Cloud Foundry versions 1.6.x through 1.6.4 GemFire broker for Cloud Foundry versions 1.7.x through 1.7.0
Description The issue concerns multiple API endpoints that do not require authentication, potentially allowing unauthorized access to the cluster managed by the broker.
Recommendations For GemFire broker for Cloud Foundry versions 1.6.x through 1.6.4, update to version 1.6.5 or later. For GemFire broker for Cloud Foundry versions 1.7.x through 1.7.0, update to version 1.7.1 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9880

Affected Products

Gemfire Broker For Cloud Foundry