CVE-2016-0883

CRITICAL

Pivotal Cloud Foundry (PCF) Ops Manager <1.5.14 & <1.6.9 - Auth Bypass

Title source: llm

Description

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.

Scores

CVSS v3 9.8
EPSS 0.0016
EPSS Percentile 36.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-287
Status draft

Affected Products (10)

pivotal_software/operations_manager < 1.5.13
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager
pivotal_software/operations_manager

Timeline

Published Sep 18, 2016
Tracked Since Feb 18, 2026