7

CVE-2019-12418

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 7.0.0 <= 7.0.97
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.47
Apache ≫ Tomcat Version >= 9.0.0 <= 9.0.28
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Oracle ≫ Workload Manager Version 12.2.0.1
Oracle ≫ Workload Manager Version 18c
Oracle ≫ Workload Manager Version 19c
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Opensuse ≫ Leap Version 15.1
Netapp ≫ Oncommand System Manager Version >= 3.0.0 <= 3.1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.648
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E
https://www.oracle.com/security-alerts/cpuapr2020.html
Patch
Third Party Advisory
https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
https://seclists.org/bugtraq/2019/Dec/43
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4596
Third Party Advisory
https://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3E
Vendor Advisory
Mailing List
https://security.gentoo.org/glsa/202003-43
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2020/dsa-4680
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20200107-0001/
Third Party Advisory
https://usn.ubuntu.com/4251-1/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/03/msg00029.html
Third Party Advisory
Mailing List
https://support.f5.com/csp/article/K10107360?utm_source=f5support&amp%3Butm_medium=RSS