5

CVE-2011-0527

VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords.

Data is provided by the National Vulnerability Database (NVD)
VMwareTc Server Version2.0.0
VMwareTc Server Version2.0.0 Updatesr01
VMwareTc Server Version2.0.1
VMwareTc Server Version2.0.2
VMwareTc Server Version2.0.2 Updatesr01
VMwareTc Server Version2.0.2 Updatesr02
VMwareTc Server Version2.0.3
VMwareTc Server Version2.0.4
VMwareTc Server Version2.0.5
VMwareTc Server Version2.0.5 Updatesr01
VMwareTc Server Version2.1.0
VMwareTc Server Version2.1.1
VMwareTc Server Version2.1.1 Updatesr01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.415
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.