VDB
CVE-2019-11286
CVE-2019-11286
PUBLISHED
CVSS 9 CRITICAL
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a crafted set of credentials leading to remote code execution.
EPSS 1.79% · 76.2th percentile
Risk Scores
CVSS 3.0
9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H
EPSS Score
1.79%
76.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| VMware Tanzu | VMware Tanzu GemFire for VMs | 1.9, 1.10, 1.11 |
| VMware Tanzu | VMware GemFire | 9.7, 9.8, 9.9 |
| vmware | gemfire | 9.9.0, 9.8.0, 9.7.0 |
| vmware | tanzu_gemfire_for_virtual_machines | 1.8.0, 1.9.0, 1.10.0 |
Timeline
- Jul 31, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- May 24, 2022 CVE Updated
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score