CVE-2016-0883: Critical severity pivotal operations manager vulnerability
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0883?
CVE-2016-0883 is considered a medium severity vulnerability due to its potential for session authentication bypass.
How do I fix CVE-2016-0883?
To fix CVE-2016-0883, upgrade Pivotal Cloud Foundry Ops Manager to version 1.5.14 or higher, or 1.6.9 or higher.
What systems are affected by CVE-2016-0883?
CVE-2016-0883 affects Pivotal Cloud Foundry Ops Manager versions 1.5.13 and earlier, and 1.6.0 to 1.6.8.
What is the impact of CVE-2016-0883?
The impact of CVE-2016-0883 is that it allows remote attackers to bypass session authentication if they have knowledge of the shared cookie-encryption key.
Who should be concerned about CVE-2016-0883?
Organizations using affected versions of Pivotal Cloud Foundry Ops Manager should be concerned about CVE-2016-0883 due to its security implications.