Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-5396

VMware GemFire: JMX insecure default lets users create an MLet MBean without a SecurityManager

Technology

GemFire / Geode

CVSS Score

8.8 / 10.0

Affected Versions

VMware GemFire before 9.7.6, 9.8.0 to 9.8.6 and 9.9.0 to 9.9.1; Tanzu GemFire for VMs before 1.10.2 and 1.11.1

Upstream Fix

GemFire 9.7.6, 9.8.7, 9.9.2, 9.10.0

Published

July 31, 2020

OSSeva Coverage

Fixed upstream

Description

When GemFire is deployed without a SecurityManager, its JMX service has an insecure default configuration that lets a user create an MLet MBean, leading to remote code execution. Clusters running with a SecurityManager are not affected.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running VMware GemFire before 9.7.6, 9.8.0 to 9.8.6 and 9.9.0 to 9.9.1; Tanzu GemFire for VMs before 1.10.2 and 1.11.1, you need this patch. Book a discovery call to get covered.