Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-12418
HistoryDec 23, 2019 - 6:15 p.m.

Design/Logic Flaw

2019-12-2318:15:00
PRIOn knowledge base
www.prio-n.com
12

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.3%

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

References