CVE Database
/

CVE-2020-5396

Back to search

CVE-2020-5396

Published: Jul 31, 2020

Modified: Sep 16, 2024

PUBLISHED

Description

VMware GemFire versions prior to 9.10.0, 9.9.2, 9.8.7, and 9.7.6, and VMware Tanzu GemFire for VMs versions prior to 1.11.1 and 1.10.2, when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration. This allows a malicious user to create an MLet mbean leading to remote code execution.

VendorProductVersions

VMware Tanzu

VMware Tanzu GemFire for VMs

affected
1.10 - < 1.10.2
affected
1.11 - < 1.11.1

VMware Tanzu

VMware GemFire

affected
9.7 - < 9.7.6
affected
9.8 - < 9.8.7
affected
9.9 - < 9.9.2
affected
9.10 - < 9.10.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now