HIGH
JMX Insecure Default Configuration in GemFire
Published Jul 31, 2020
8.8
HIGHCVSS 3.1
EPSS 1.89%
Description
VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading to remote code execution.
Affected products
-
- Version 9.10StatusaffectedConstraints<9.10.0
- Version 9.7StatusaffectedConstraints<9.7.6
- Version 9.8StatusaffectedConstraints<9.8.7
- Version 9.9StatusaffectedConstraints<9.9.2
- Version
-
- Version 1.10StatusaffectedConstraints<1.10.2
- Version 1.11StatusaffectedConstraints<1.11.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| VMware Tanzu | VMware GemFire | n/a |
| |||||||||||||||
| VMware Tanzu | VMware Tanzu GemFire for VMs | n/a |
|
Configuration 1
Configuration 2
OR
- ≥ 1.10.0 · < 1.10.2
- ≥ 1.11.0 · < 1.11.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (1)
- https://tanzu.vmware.com/security/cve-2020-5396 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://tanzu.vmware.com/security/cve-2020-5396 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Jul 31, 2020
Updated Sep 16, 2024
Reserved Jan 3, 2020
Link CVE-2020-5396
CISA Vulnrichment
Updated n/a