CVE-2016-4435 - CVE House
Back to Database
Status published Critical CVE-2016-4435

An endpoint of the Agent running on the BOSH Director...

Vulnerability Description

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-4435

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cloud Foundry
Vulnerable Versions:
BOSH stemcell versions prior to 3232.6 and 3146.13

Timeline

Official Publish: May 25th, 2017
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.