CVE-2016-9880

CRITICAL

GemFire for Pivotal Cloud Foundry 1.6.0-1.6.4 and 1.7.0 - Unauthenticated Cluster Access via API Endpoints

Title source: llm
STIX 2.1

Description

The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2016-9880
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96146

Scores

CVSS v3 9.8
EPSS 0.0216
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
pivotal_software/gemfire_for_pivotal_cloud_foundry 1.7.0
pivotal_software/gemfire_for_pivotal_cloud_foundry 1.6.0 - 1.6.5
Published Mar 16, 2018
Tracked Since Feb 18, 2026