6
CVSSv2

CVE-2020-5414

Published: 31/07/2020 Updated: 04/08/2020
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.7 | Impact Score: 4.7 | Exploitability Score: 0.9
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

VMware Tanzu Application Service for VMs (2.7.x versions before 2.7.19, 2.8.x versions before 2.8.13, and 2.9.x versions before 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to authenticated users of the BOSH Director. This credential would grant administrative privileges to a malicious user. The same versions of App Autoscaler also log the App Autoscaler Broker password. Prior to newer versions of Operations Manager, this credential was not redacted from logs. This credential allows a malicious user to create, delete, and modify App Autoscaler services instances. Operations Manager started redacting this credential from logs as of its versions 2.7.15, 2.8.6, and 2.9.1. Note that these logs are typically only visible to foundation administrators and operators.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware tanzu application service for virtual machines

vmware operations manager