CVE-2019-11286 Information

Description

VMware GemFire versions prior to 9.10.0 9.9.1 9.8.5 and 9.7.5 and VMware Tanzu GemFire for VMs versions prior to 1.11.0 1.10.1 1.9.2 and 1.8.2 contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a crafted set of credentials leading to remote code execution.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Reference

https://tanzu.vmware.com/security/cve-2019-11286

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.1

Share on: