← Back

CVE-2019-12418

nvd nist
Published: Dec 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

Affected (12)

Products: Apache: Tomcat · Debian: Debian Linux · Oracle: Workload Manager · +3 more
Show all products
1 product
Tomcat
1 product
Debian Linux
1 product
Workload Manager
1 product
Ubuntu Linux
1 product
Leap
1 product
Oncommand System Manager
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 7.0.0 to 7.0.97
From 8.5.0 to 8.5.47
From 9.0.0 to 9.0.28
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.2.0.1
Version 18c
Version 19c
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 16.04
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
From 3.0.0 to 3.1.3

References (34)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.