← Back

CVE-2016-4435

nvd nist
Published: May 25, 2017Modified: May 13, 2026

JSON object

Loading...
9.0
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

Affected (2)

1 product
Bosh Stemcell
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Pivotal
Up to 3232.4
Version 3146.13

Related CWEs

References (2)

Source: security_alert@emc.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.