Vulnerabilities > Pivotal Software > Gemfire FOR Pivotal Cloud Foundry > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-16 CVE-2016-9880 Improper Authentication vulnerability in Pivotal Software Gemfire for Pivotal Cloud Foundry 1.7.0
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
network
low complexity
pivotal-software CWE-287
7.5
2017-01-06 CVE-2016-9885 Information Exposure vulnerability in Pivotal Software Gemfire FOR Pivotal Cloud Foundry
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1.
network
low complexity
pivotal-software CWE-200
7.5