Vulnerability Details CVE-2019-11286
                VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input. A remote authenticated malicious user may request against the service with a crafted set of credentials leading to remote code execution.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.027
                        
                    
                    
                        
                            EPSS Ranking 85.5%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 9.0
                        
                    
                    
                        
                            CVSS v2 Score 6.5
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2019-11286
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:gemfire:9.7.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:gemfire:9.8.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:gemfire:9.9.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:tanzu_gemfire_for_virtual_machines:*
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:a:vmware:tanzu_gemfire_for_virtual_machines:1.10.0