Vulnerability Description
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runtime 1.8.x versions to 1.8.12 or later. Upgrade PCF Ops Manager 1.7.x versions to 1.7.18 or later and 1.8.x versions to 1.8.10 or later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Cloud Foundry Ops Manager | 1.7.0 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94126Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-6657MitigationVendor Advisory
- http://www.securityfocus.com/bid/94126Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-6657MitigationVendor Advisory
FAQ
What is CVE-2016-6657?
CVE-2016-6657 is a vulnerability with a CVSS score of 7.4 (HIGH). An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runti...
How severe is CVE-2016-6657?
CVE-2016-6657 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-6657?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Cloud Foundry Ops Manager, Pivotal Software Cloud Foundry Elastic Runtime.