QID 375428

Date Published: 2021-06-10

QID 375428: VMware GemFire Remote Code Execution Vulnerability

VMware GemFire is a distributed data management platform. Pivotal GemFire is designed for many diverse data management situations, but is especially useful for high-volume, latency-sensitive, mission-critical, transactional systems.

VMware GemFire when deployed without a SecurityManager, contain a JMX service available which contains an insecure default configuration.

Affected Versions
VMware GemFire versions prior to 9.9.2
VMware GemFire versions prior to 9.8.7 and
VMware GemFire versions prior to 9.7.6

QID Detection Logic
This QID checks for the vulnerable version of VMware GemFire on system

On successful exploitation, this vulnerability allows a malicious user to create an MLet mbean leading to remote code execution.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Users of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:
    VMware GemFire 9.7.6
    VMware GemFire 9.8.7
    VMware GemFire 9.9.2
    VMware GemFire 9.10.0
    Refer to CVE-2020-5396 to obtain additional details.
    Vendor References

    CVEs related to QID 375428

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-5396 URL Logo tanzu.vmware.com/security/cve-2020-5396