Permissions, Privileges, and Access Controls in VMware Tanzu Application Service for VMs and VMware Tanzu Operations Manager - CVE-2020-5414
Published: August 3, 2020
Vulnerability identifier: #VU32994
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5414
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the App Autoscaler logs the UAA admin password. A remote authenticated attacker can gain administrative privileges on the target system.
Affected software
VMware Tanzu Application Service for VMs
VMware Tanzu Operations Manager
VMware Tanzu Operations Manager
How to mitigate CVE-2020-5414
Install updates from vendor's website.
VMware Tanzu Application Service for VMs - addressed in versions 2.7.19, 2.8.13, 2.9.7
VMware Tanzu Operations Manager - addressed in versions 2.7.15, 2.8.6, 2.9.1
VMware Tanzu Operations Manager - addressed in versions 2.7.15, 2.8.6, 2.9.1