Release date:
Updated on:
Affected Systems:
VMWare vFabric tc Server 2.x
Unaffected system:
VMWare vFabric tc Server 2.1.2
VMWare vFabric tc Server 2.0.6
Description:
--------------------------------------------------------------------------------
Bugtraq id: 49122
CVE (CAN) ID: CVE-2011-0527
VFabric tc Server is a Server for building and running Java Spring applications at the enterprise level. It can meet the needs of its operation management, advanced analysis, and key task support.
VFabric tc Server's Security Restriction Bypass Vulnerability in JMX authentication. Remote attackers can exploit this vulnerability to bypass certain security restrictions and obtain unauthorized access.
<* Source: SpringSource tc Server support team
Link: http://www.springsource.com/security/cve-2011-0527
Http://www.vmware.com/products/vfabric-tcserver/overview.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com