CVE-2016-0883
CRITICALPivotal Cloud Foundry (PCF) Ops Manager <1.5.14 & <1.6.9 - Auth Bypass
Title source: llmDescription
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
Scores
CVSS v3
9.8
EPSS
0.0016
EPSS Percentile
36.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-287
Status
draft
Affected Products (10)
pivotal_software/operations_manager
< 1.5.13
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
Timeline
Published
Sep 18, 2016
Tracked Since
Feb 18, 2026