Lucene search

K
cvelistApacheCVELIST:CVE-2019-12418
HistoryDec 23, 2019 - 5:12 p.m.

CVE-2019-12418

2019-12-2317:12:43
apache
www.cve.org
8

AI Score

7.4

Confidence

High

EPSS

0.001

Percentile

17.2%

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

CNA Affected

[
  {
    "product": "Apache Tomcat",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "9.0.0.M1 to 9.0.28"
      },
      {
        "status": "affected",
        "version": "8.5.0 to 8.5.47"
      },
      {
        "status": "affected",
        "version": "7.0.0 to 7.0.97"
      }
    ]
  }
]

References