VYPR

GemFire

by Cloudfoundry

CVEs (2)

  • CVE-2016-9885CriJan 6, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticated and publicly accessible. Because…

  • CVE-2016-8220HigApr 18, 2018
    risk 0.49cvss 7.5epss 0.01

    Pivotal Gemfire for PCF, versions 1.6.x prior to 1.6.5.0 and 1.7.x prior to 1.7.1.0, contain an information disclosure vulnerability. The application inadvertently exposed WAN replication credentials at a public route.