Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2019-11286

VMware GemFire: network JMX service allows remote code execution with crafted credentials

Technology

GemFire / Geode

CVSS Score

9.1 / 10.0

Affected Versions

VMware GemFire before 9.7.5, 9.8.0 to 9.8.4 and 9.9.0; Tanzu GemFire for VMs before 1.8.2, 1.9.2, 1.10.1 and 1.11.0

Upstream Fix

GemFire 9.7.5, 9.8.5, 9.9.1, 9.10.0

Published

July 31, 2020

OSSeva Coverage

Fixed upstream

Description

GemFire exposes a JMX service on the network that does not properly restrict input. A remote authenticated user can send a crafted set of credentials that leads to remote code execution.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running VMware GemFire before 9.7.5, 9.8.0 to 9.8.4 and 9.9.0; Tanzu GemFire for VMs before 1.8.2, 1.9.2, 1.10.1 and 1.11.0, you need this patch. Book a discovery call to get covered.