« Volver al listado

CVE-2020-5406

Estado: ModificadaMedia (6.5)—

VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5406",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@pivotal.io",
      "affectedData": [
        {
          "vendor": "Pivotal",
          "product": "VMware Tanzu Application Service for VMs",
          "versions": [
            {
              "status": "affected",
              "version": "2.8.x",
              "lessThan": "2.8.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.7.x",
              "lessThan": "2.7.11",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.6.x",
              "lessThan": "2.6.18",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-10T19:15:13.507",
  "references": [
    {
      "url": "https://tanzu.vmware.com/security/cve-2020-5406",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@pivotal.io"
    },
    {
      "url": "https://tanzu.vmware.com/security/cve-2020-5406",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@pivotal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling."
    },
    {
      "lang": "es",
      "value": "VMware Tanzu Application Service para Máquinas Virtuales, versiones 2.6.x anteriores a 2.6.18, versiones 2.7.x anteriores a 2.7.11 y versiones 2.8.x anteriores a 2.8.5, incluye una versión de PCF Autoscaling que escribe las propiedades de conexión de la base de datos en su registro, incluyendo el nombre de usuario y la contraseña de la base de datos. Un usuario malicioso con acceso a esos registros puede conseguir acceso no autorizado a la base de datos que está siendo usada por Autoscaling."
    }
  ],
  "lastModified": "2026-06-17T03:21:26.090",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:tanzu_application_service_for_vms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E744C18C-CBD7-45C4-9F6C-6C62958772E6",
              "versionEndExcluding": "2.6.18",
              "versionStartIncluding": "2.6.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:tanzu_application_service_for_vms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97B0FC3C-42D8-4967-B38E-5D737C00D7E1",
              "versionEndExcluding": "2.7.11",
              "versionStartIncluding": "2.7.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:tanzu_application_service_for_vms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A76837B4-89DF-4CBF-9A47-190FA6110076",
              "versionEndExcluding": "2.8.5",
              "versionStartIncluding": "2.8.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@pivotal.io"
}