CVE-2016-9880: Pivotal Software Gemfire For Pivotal Cloud Foundry
Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.
The GemFire broker for Cloud Foundry 1.6.x before 1.6.5 and 1.7.x before 1.7.1 has multiple API endpoints which do not require authentication and could be used to gain access to the cluster managed by the broker.
Affected products
- Pivotal Software Gemfire For Pivotal Cloud Foundry: from 1.6.0, before 1.6.5 (fixed in 1.6.5); version 1.7.0 only
Published 2018-03-16. Last modified 2026-06-17.