« Volver al listado

CVE-2016-0883

Estado: ModificadaCrítica (9.8)—

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-0883",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-09-18T02:59:00.150",
  "references": [
    {
      "url": "https://pivotal.io/security/pcf-ops-manager-weak-authentication-scheme",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://pivotal.io/security/pcf-ops-manager-weak-authentication-scheme",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation."
    },
    {
      "lang": "es",
      "value": "Pivotal Cloud Foundry (PCF) Ops Manager en versiones anteriores a 1.5.14 y 1.6.x en versiones anteriores a 1.6.9 usa la misma clave de cifrado de cookies a través instalaciones de clientes diferentes, lo que permite a atacantes remotos eludir autenticación de sesión mediante el aprovechamiento del conocimiento de esta clave desde otra instalación."
    }
  ],
  "lastModified": "2026-06-17T00:38:24.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42ADBC47-EDCB-4264-9C23-1CA7E37F22E3",
              "versionEndIncluding": "1.5.13"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28E4F479-F7CA-4712-9FCD-BCA81FE158AA"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D65021E-B67D-4EF1-A131-87D46BDDC625"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71F33A0C-470C-469E-8CB7-B5CF2E4397F4"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2EB51900-C380-4996-B57B-2588970C4BAC"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D75AAFC-E49B-4539-B1D4-15589F0E0BE3"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBA9E4C0-89AD-4983-9E5A-24B2240D580F"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2468F8D1-05CE-4416-BF34-B23F6CA87E2D"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ACA3E75B-AE5E-4A5B-A11B-E1AA99B4BFBB"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:1.6.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CBB83FC-8578-427E-A71D-78BE93A0A354"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}