6.8
CVSSv2

CVE-2010-1454

Published: 19/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 prior to 6.0.20.D, and 6.0.25.A prior to 6.0.25.A-SR01, does not properly enforce the requirement for an encrypted (aka s2enc) password, which allows remote malicious users to obtain JMX interface access via a blank password.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware tc server 6.0.25.a

vmware tc server 6.0.20.a

vmware tc server 6.0.19.a

vmware tc server 6.0.20

vmware tc server 6.0.20.b

vmware tc server 6.0.20.c

vmware tc server 6.0.19