CVE-2011-0527
VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging…
Does this matter?
Lower severity and a low EPSS score (1.56%). Track it; it rarely justifies an emergency change on its own.
Description
VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.56% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- vmware/tc server
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0122.html
- http://securitytracker.com/id?1025923
- http://www.securityfocus.com/bid/49122
- http://www.springsource.com/security/cve-2011-0527Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69156
- http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0122.html
- http://securitytracker.com/id?1025923
- http://www.securityfocus.com/bid/49122
- http://www.springsource.com/security/cve-2011-0527Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69156
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.