CVE-2016-9880: Critical severity Pivotal Software Gemfire For Pivotal Cloud Foundry vulnerability
Published Mar 16, 2018
·Updated
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
Affected Software
2 affected components
Pivotal Software Gemfire For Pivotal Cloud Foundry>=1.6.0<1.6.5
Pivotal Software Gemfire For Pivotal Cloud Foundry=1.7.0
Event History
Mar 16, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-9880?
CVE-2016-9880 is classified as a high severity vulnerability due to multiple unauthenticated API endpoints.
2
How do I fix CVE-2016-9880?
To fix CVE-2016-9880, upgrade to GemFire for Cloud Foundry version 1.6.5 or higher, or 1.7.1 or higher.
3
What software is affected by CVE-2016-9880?
CVE-2016-9880 affects GemFire for Pivotal Cloud Foundry versions 1.6.x before 1.6.5 and 1.7.x before 1.7.1.
4
What risks are associated with CVE-2016-9880?
The risks of CVE-2016-9880 include unauthorized access to the cluster managed by the GemFire broker.
5
Is authentication required for the vulnerable API endpoints in CVE-2016-9880?
No, the vulnerable API endpoints in CVE-2016-9880 do not require authentication, allowing potential exploitation.