Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22226
HistoryDec 23, 2019 - 8:45 a.m.

Privilege Escalation

2019-12-2308:45:46
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

EPSS

0.001

Percentile

17.2%

Tomcat-catalina is vulnerable to privilege escalation. When JMX Remote Lifecycle Listener is used to configure Tomcat, a local attack is possible to access Tomcat process or configuration files and manipulate RMI registry, thereby allowing the attacker to act as man-in-the-middle (MitM) to steal the the credential for JMX interface and to get full control over JMX instance.

References