Vulnerabilities > CVE-2016-0896 - 7PK - Security Features vulnerability in Pivotal Software Cloud Foundry Elastic Runtime

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pivotal-software
CWE-254

Summary

Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address.

Vulnerable Configurations

Part Description Count
Application
Pivotal_Software
45

Common Weakness Enumeration (CWE)