Vulnerability Description
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Operations Manager | <= 1.5.13 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/pcf-ops-manager-weak-authentication-schemeVendor Advisory
- https://pivotal.io/security/pcf-ops-manager-weak-authentication-schemeVendor Advisory
FAQ
What is CVE-2016-0883?
CVE-2016-0883 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass sess...
How severe is CVE-2016-0883?
CVE-2016-0883 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-0883?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Operations Manager.