CVE-2016-6639
Estado: ModificadaAlta (7.5)—
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.70%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-254
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-6639",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2016-09-18T02:59:12.463",
"references": [
{
"url": "https://github.com/cloudfoundry/php-buildpack/commit/e2db3ccd4812e0c0aba20720fc51789d981aba67",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "https://pivotal.io/security/cve-2016-6639",
"tags": [
"Vendor Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "https://github.com/cloudfoundry/php-buildpack/commit/e2db3ccd4812e0c0aba20720fc51789d981aba67",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://pivotal.io/security/cve-2016-6639",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-254"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file."
},
{
"lang": "es",
"value": "Cloud Foundry PHP Buildpack (también conocido como php-buildpack) en versiones anteriores a 4.3.18 y PHP Buildpack Cf-release en versiones anteriores a 242, como se usa en Pivotal Cloud Foundry (PCF) Elastic Runtime en versiones anteriores a 1.6.38 y 1.7.x en versiones anteriores a 1.7.19 y otros productos, sitúa el archivo .profile en el directorio htdocs, lo que podría permitir a atacantes remotos obtener información sensible a través de una petición HTTP GET para este archivo."
}
],
"lastModified": "2026-06-17T00:51:30.977",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cloudfoundry:php-buildpack:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5F973A97-A2A7-44C4-B3A3-17EB2790F243",
"versionEndIncluding": "4.3.17"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A333798B-74F5-4C64-A80E-2A44C676F33E",
"versionEndIncluding": "1.6.37"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D459191E-DE3B-4F17-9F69-FFF3D000ADD5"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8943CF5B-DA24-4FF3-92B2-43EFE963B59E"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45076F48-C883-4334-95EE-F00266D9EBA8"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40D1DC46-1AD9-429F-A4D8-875D9B4B18BE"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7B0ACEB5-8D35-426B-B911-E04ACFC09B09"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3C00AC47-7617-42AB-9403-A7494DDB94CF"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D0A39E28-6AF2-42DA-BC0F-857D835D9BF4"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12D89F4D-16EB-4F51-B64E-7E79DCC6E8CE"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9A5C3633-7F63-4E38-BCA2-8F884CC9918C"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D566285-755F-4607-8E88-78B39178E2F5"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE0B85D3-61EB-4EF5-919A-38D838204D5B"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.11:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90F19FD0-FA81-458C-A80B-EE638D40DE5E"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4D1DDBA-18D2-4142-B71D-10BBEAB8481B"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEC7CD4D-2F58-4986-9CE4-5A4514759F6C"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.14:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5CF1E9E-8C76-4B93-8CE9-B9CA77F4495D"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61EAA0FB-2D32-486D-9177-53EDB2545279"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "219CDE5B-DC6B-4BFF-BD9C-EC1ED86A286F"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C31708C5-7FA6-4960-8303-391EDC5889ED"
},
{
"criteria": "cpe:2.3:a:pivotal:cloud_foundry_elastic_runtime:1.7.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DAE910A-0240-47FD-B5A3-788B3EC5E5D0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}