VulnerabilityModified
CVE-2016-9880
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
CRITICAL 9.8EPSS 2.05%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- pivotal software/gemfire for pivotal cloud foundry
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/96146Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2016-9880Vendor Advisory
- http://www.securityfocus.com/bid/96146Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2016-9880Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.