CVE-2016-9880

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
References
Link Resource
https://pivotal.io/security/cve-2016-9880 Vendor Advisory
http://www.securityfocus.com/bid/96146 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pivotal_software:gemfire_for_pivotal_cloud_foundry:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:gemfire_for_pivotal_cloud_foundry:1.7.0:*:*:*:*:*:*:*

Information

Published : 2018-03-16 13:29

Updated : 2018-04-10 06:38


NVD link : CVE-2016-9880

Mitre link : CVE-2016-9880


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

pivotal_software

  • gemfire_for_pivotal_cloud_foundry