Security Advisory

CVE-2016-0883

9.8
CRITICAL

Vulnerability Description

Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
Published Date September 18, 2016
Official Source NIST NVD Advisory