| Vulnerability Name: | CVE-2010-1454 (CCN-58684) | ||||||||
| Assigned: | 2010-05-13 | ||||||||
| Published: | 2010-05-13 | ||||||||
| Updated: | 2018-10-10 | ||||||||
| Summary: | com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25.A before 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which allows remote attackers to obtain JMX interface access via a blank password. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||
| References: | Source: MITRE Type: CNA CVE-2010-1454 Source: CCN Type: SA39778 SpringSource tc Server Encrypted Password Security Bypass Source: SECUNIA Type: Vendor Advisory 39778 Source: CCN Type: OSVDB ID: 64724 SpringSource tc Server com.springsource.tcserver.serviceability.rmi.JmxSocketListener Encrypted Password Handling Authentication Bypass Source: BUGTRAQ Type: UNKNOWN 20100517 CVE-2010-1454: SpringSource tc Server unauthenticated remote access to JMX interface Source: BID Type: UNKNOWN 40205 Source: CCN Type: BID-40205 SpringSource tc Server JMX Interface Authentication Security Bypass Vulnerability Source: CCN Type: SpringSource Web site SpringSource tc Server unauthenticated remote access to JMX interface Source: CONFIRM Type: Vendor Advisory http://www.springsource.com/security/cve-2010-1454 Source: XF Type: UNKNOWN tcserver-listener-security-bypass(58684) Source: XF Type: UNKNOWN tcserver-listener-security-bypass(58684) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||