CVE-2016-9877
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Un problema fue descubierto en Pivotal RabbitMQ 3.x en versiones anteriores a 3.5.8 y 3.6.x en versiones anteriores a 3.6.6 y RabbitMQ for PCF 1.5.x en versiones anteriores a 1.5.20, 1.6.x en versiones anteriores a 1.6.12 y 1.7.x en versiones anteriores a 1.7.7. Autenticación de conexión MQTT (MQ Telemetry Transport) con un nombre de usuario/contraseña tiene éxito si se provee un nombre de usuario existente pero la contraseña es omitida de la petición de conexión. Conexiones que usan TLS con un certificado provisto por el cliente no están afectadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-06 CVE Reserved
- 2016-12-29 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95065 | Vdb Entry | |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03880en_us | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3761 | 2022-03-17 | |
https://pivotal.io/security/cve-2016-9877 | 2022-03-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.5.4 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.5.4" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.5.5 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.5.5" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.5.7 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.5.7" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.0 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.0" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.1 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.1" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.2 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.2" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.3 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.3" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.4 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.4" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 3.6.5 Search vendor "Pivotal Software" for product "Rabbitmq" and version "3.6.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.0.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.0.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.0.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.0.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.0.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.0.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.0.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.0.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.0.4 Search vendor "Vmware" for product "Rabbitmq" and version "3.0.4" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.4 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.4" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.1.5 Search vendor "Vmware" for product "Rabbitmq" and version "3.1.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.2.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.2.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.2.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.2.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.2.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.2.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.2.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.2.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.2.4 Search vendor "Vmware" for product "Rabbitmq" and version "3.2.4" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.4 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.4" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.3.5 Search vendor "Vmware" for product "Rabbitmq" and version "3.3.5" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.4.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.4.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.4.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.4.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.4.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.4.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.4.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.4.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.4.4 Search vendor "Vmware" for product "Rabbitmq" and version "3.4.4" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.5.0 Search vendor "Vmware" for product "Rabbitmq" and version "3.5.0" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.5.1 Search vendor "Vmware" for product "Rabbitmq" and version "3.5.1" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.5.2 Search vendor "Vmware" for product "Rabbitmq" and version "3.5.2" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.5.3 Search vendor "Vmware" for product "Rabbitmq" and version "3.5.3" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | 3.5.6 Search vendor "Vmware" for product "Rabbitmq" and version "3.5.6" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.0 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.0" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.1 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.1" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.2 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.2" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.3 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.3" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.4 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.4" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.5 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.5" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.6 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.6" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.7 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.7" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.8 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.8" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.9 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.9" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.10 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.10" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.11 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.11" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.12 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.12" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.13 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.13" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.14 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.14" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.15 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.15" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.17 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.17" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.5.18 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.5.18" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.0 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.0" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.1 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.1" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.2 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.2" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.3 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.3" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.4 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.4" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.5 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.5" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.6 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.6" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.7 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.7" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.8 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.8" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.9 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.9" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.6.10 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.6.10" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.0 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.0" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.2 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.2" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.3 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.3" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.4 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.4" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.5 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.5" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | 1.7.6 Search vendor "Pivotal Software" for product "Rabbitmq" and version "1.7.6" | pivotal_cloud_foundry |
Affected
|