CVE-2019-11288 is a high-severity vulnerability affecting Pivotal tc Server and tc Runtimes, allowing a local attacker to intercept JMX credentials when the JMX Socket Listener is enabled. This man-in-the-middle attack enables the attacker to gain full control over the tc Runtime instance. The CVSS score is 7.0 (High), indicating a local attack vector with high impact on confidentiality, integrity, and availability, but with high attack complexity. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.70.b, < 7.0.99.bCPE matchmatch criteria | cpe:2.3:a:pivotal:tc_runtimes:*:*:*:*:*:*:*:* | ||
>= 8.5.4.b, < 8.5.47.aCPE matchmatch criteria | cpe:2.3:a:pivotal:tc_runtimes:*:*:*:*:*:*:*:* | ||
>= 9.0.6.b, < 9.0.27.aCPE matchmatch criteria | cpe:2.3:a:pivotal:tc_runtimes:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.2.19CPE matchmatch criteria | cpe:2.3:a:pivotal:tc_server:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.10CPE matchmatch criteria | cpe:2.3:a:pivotal:tc_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.