CVE-2011-0527

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/08/2011
Last modified:
11/04/2025

Description

VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during JMX authentication, which makes it easier for context-dependent attackers to obtain access by leveraging an ability to read stored passwords.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:tc_server:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.0:sr01:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.2:sr01:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.2:sr02:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.0.5:sr01:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:tc_server:2.1.1:sr01:*:*:*:*:*:*