Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0883

Опубликовано: 18 сент. 2016
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*
Версия до 1.5.13 (включая)
cpe:2.3:a:pivotal_software:operations_manager:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:pivotal_software:operations_manager:1.6.8:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287