Vulnerabilities > Vmware > Tanzu Gemfire FOR Virtual Machines > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-07-31 CVE-2019-11286 Deserialization of Untrusted Data vulnerability in VMWare Gemfire and Tanzu Gemfire for Virtual Machines
VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.11.0, 1.10.1, 1.9.2, and 1.8.2, contain a JMX service available to the network which does not properly restrict input.
network
low complexity
vmware CWE-502
critical
9.1