CVE-2016-4435

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
References
Link Resource
https://pivotal.io/security/cve-2016-4435 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pivotal:bosh_stemcell:3146.13:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:bosh_stemcell:*:*:*:*:*:*:*:*

Information

Published : 2017-05-25 10:29

Updated : 2017-10-02 08:28


NVD link : CVE-2016-4435

Mitre link : CVE-2016-4435


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

pivotal

  • bosh_stemcell