Configuration in VMware Tanzu GemFire for VMs and VMware GemFire - CVE-2020-5396
Published: August 3, 2020
Vulnerability identifier: #VU32997
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5396
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exixts due to a JMX service contains an insecure default configuration. A remote authenticated attacker can create an MLet mbean and execute arbitrary code on the target system.
Affected software
VMware Tanzu GemFire for VMs
VMware GemFire
VMware GemFire
How to mitigate CVE-2020-5396
Install updates from vendor's website.
VMware Tanzu GemFire for VMs - addressed in versions 1.10.2, 1.11.1
VMware GemFire - addressed in versions 9.7.6, 9.8.7, 9.9.2
VMware GemFire - addressed in versions 9.7.6, 9.8.7, 9.9.2