Lucene search

K
f5F5F5:K10107360
HistoryJan 07, 2020 - 12:00 a.m.

K10107360 : Apache Tomcat vulnerability CVE-2019-12418

2020-01-0700:00:00
my.f5.com
58

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

17.2%

Security Advisory Description

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance. (CVE-2019-12418)

Impact

There is no impact; F5 products are not affected by this vulnerability.