CVE-2016-8220: Pivotal Software Gemfire

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application inadvertently exposed WAN replication credentials at a public route.

Affected products

  • Pivotal Software Gemfire: from 1.6.0.0, before 1.6.5.0 (fixed in 1.6.5.0); from 1.7.0.0, before 1.7.1.0 (fixed in 1.7.1.0)

Published 2018-04-18. Last modified 2026-06-17.