CVE-2019-12418
published 2019-12-23CVE-2019-12418: When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access…
PriorityP335high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
1.22%
65.3th percentile
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | 7.0.0 – 7.0.97 | — |
| apache | tomcat | 8.5.0 – 8.5.47 | — |
| apache | tomcat | 9.0.0 – 9.0.28 | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.31-1 (bookworm) | tomcat9 9.0.31-1 (bookworm) |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| opensuse | leap | — | — |
| oracle | workload_manager | — | — |
| oracle | workload_manager | — | — |
| oracle | workload_manager | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_apache7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2020-01-27·CVSS 7.0
CVE-2019-12418 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled the RMI registry when
configured with the JMX Remote Lifecycle Listener. A local attacker could
possibly use this issue to obtain credentials and gain complete control
over the Tomcat instance. (CVE-2019-12418)
It was discovered that Tomcat incorrectly handled FORM authentication. A
remote attacker could possibly use this issue to perform a session fixation
attack. (CVE-2019-17563)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: local privilege escalation
vendor_redhat·2019-11-21·CVSS 7.0
CVE-2019-12418 [HIGH] CWE-284 tomcat: local privilege escalation
tomcat: local privilege escalation
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
A privilege escalation flaw was found in Tomcat when the JMX Remote Lifecycle Listener was enabled. A local attacker without access to the Tomcat process or configuration files could be able to manipulate the RMI registry to perform a man-in-the-middle attack. The attacker could then cap
Debian
CVE-2019-12418: tomcat9 - When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is conf...
vendor_debian·2019·CVSS 7.0
CVE-2019-12418 [HIGH] CVE-2019-12418: tomcat9 - When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is conf...
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Scope: local
bookworm: resolved (fixed in 9.0.31-1)
bullseye: resolved (fixed in 9.0.31-1)
forky: resolved (fixed in 9.0.31-1)
sid: resolved (fixed in 9.0.31-1)
trixie: resolved (fixed in 9.0.31-1)
Apache
Apache tomcat: CVE-2019-12418
vendor_apache·CVSS 7.0
CVE-2019-12418 [HIGH] Apache tomcat: CVE-2019-12418
Apache tomcat: CVE-2019-12418
When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance. The JMX Remote Lifecycle Listener will be deprecated in future Tomcat releases, will be removed for Tomcat 10 and may be removed from all Tomcat releases some time after 31 December 2020. Users should also be aware of
OSV
tomcat8 vulnerabilities
osv·2020-01-27·CVSS 7.0
CVE-2019-12418 [HIGH] tomcat8 vulnerabilities
tomcat8 vulnerabilities
It was discovered that Tomcat incorrectly handled the RMI registry when
configured with the JMX Remote Lifecycle Listener. A local attacker could
possibly use this issue to obtain credentials and gain complete control
over the Tomcat instance. (CVE-2019-12418)
It was discovered that Tomcat incorrectly handled FORM authentication. A
remote attacker could possibly use this issue to perform a session fixation
attack. (CVE-2019-17563)
GHSA
Insufficiently Protected Credentials in Apache Tomcat
ghsa·2019-12-26
CVE-2019-12418 [HIGH] CWE-522 Insufficiently Protected Credentials in Apache Tomcat
Insufficiently Protected Credentials in Apache Tomcat
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
OSV
Insufficiently Protected Credentials in Apache Tomcat
osv·2019-12-26
CVE-2019-12418 [HIGH] Insufficiently Protected Credentials in Apache Tomcat
Insufficiently Protected Credentials in Apache Tomcat
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
OSV
CVE-2019-12418: When Apache Tomcat 9
osv·2019-12-23·CVSS 7.0
CVE-2019-12418 [HIGH] CVE-2019-12418: When Apache Tomcat 9
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
No detection rules found.
No public exploits indexed.
HackerOne
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
hackerone·2020-06-11·CVSS 4.3
[MEDIUM] Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
**Summary:**
There are multiple issues found on ███:
1. ███████/examples/ - Apache Tomcat examples are available for public. Multiple issues - session and cookies manipulation, internals IP disclosure.
2. Error page contains information about Apache Tomcat version
3. Reported Tomcat version is vulnerable. Multiple CVEs - critical, high and medium
**Description:**
1. Examples are available by link: ███████/examples/
2. Information disclosure about Apache Tomcat version
3. Vulnerable version Apache Tomcat/8.5.33
https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Base Score: 9.8 CRITICALVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2019-0232
Base Score
Bugzilla
CVE-2019-12418 tomcat: local privilege escalation [epel-all]
bugzilla·2019-12-20·CVSS 7.0
CVE-2019-12418 [HIGH] CVE-2019-12418 tomcat: local privilege escalation [epel-all]
CVE-2019-12418 tomcat: local privilege escalation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. Wh
Bugzilla
CVE-2019-12418 tomcat: local privilege escalation
bugzilla·2019-12-20·CVSS 7.0
CVE-2019-12418 [HIGH] CVE-2019-12418 tomcat: local privilege escalation
CVE-2019-12418 tomcat: local privilege escalation
When Tomcat is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Reference:
https://tomcat.apache.org/security-7.html
https://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-9.html
Upstream commits:
https://github.com/apache/tomcat/commit/bef3f40
https://github.com/apache/tomcat/commit/a91d7db
https://github.com/apache/tomcat/commit/1fc9f58
Discussion:
Created tomcat tracki
Bugzilla
CVE-2019-12418 tomcat: local privilege escalation [fedora-all]
bugzilla·2019-12-20·CVSS 7.0
CVE-2019-12418 [HIGH] CVE-2019-12418 tomcat: local privilege escalation [fedora-all]
CVE-2019-12418 tomcat: local privilege escalation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttps://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/01/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00029.htmlhttps://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200107-0001/https://support.f5.com/csp/article/K10107360?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4251-1/https://www.debian.org/security/2019/dsa-4596https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlhttps://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/01/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2020/03/msg00029.htmlhttps://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200107-0001/https://support.f5.com/csp/article/K10107360?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4251-1/https://www.debian.org/security/2019/dsa-4596https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpuapr2020.html
2019-12-23
Published