Vulnerability Description
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Gemfire For Pivotal Cloud Foundry | >= 1.6.0, < 1.6.5 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96146Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-9880Vendor Advisory
- http://www.securityfocus.com/bid/96146Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-9880Vendor Advisory
FAQ
What is CVE-2016-9880?
CVE-2016-9880 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by...
How severe is CVE-2016-9880?
CVE-2016-9880 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-9880?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Gemfire For Pivotal Cloud Foundry.