cbcvebase.
CVE-2019-12418
published 2019-12-23

CVE-2019-12418: When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access…

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

Affected

17 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat7.0.0 – 7.0.97
apachetomcat8.5.0 – 8.5.47
apachetomcat9.0.0 – 9.0.28
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiantomcat9< tomcat9 9.0.31-1 (bookworm)tomcat9 9.0.31-1 (bookworm)
netapponcommand_system_manager3.0.0 – 3.1.3
opensuseleap
oracleworkload_manager
oracleworkload_manager
oracleworkload_manager

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH