VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling.
2020-04-10T19:15:13.507
2024-11-21T05:34:05.227
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | vmware | tanzu_application_service_for_vms | < 2.6.18 | Yes |
Application | vmware | tanzu_application_service_for_vms | < 2.7.11 | Yes |
Application | vmware | tanzu_application_service_for_vms | < 2.8.5 | Yes |