7

CVE-2019-12418

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version >= 7.0.0 <= 7.0.97
ApacheTomcat Version >= 8.5.0 <= 8.5.47
ApacheTomcat Version >= 9.0.0 <= 9.0.28
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
OracleWorkload Manager Version12.2.0.1
OracleWorkload Manager Version18c
OracleWorkload Manager Version19c
CanonicalUbuntu Linux Version16.04 SwEditionesm
OpensuseLeap Version15.1
NetappOncommand System Manager Version >= 3.0.0 <= 3.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.87% 0.744
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
https://seclists.org/bugtraq/2019/Dec/43
Third Party Advisory
Mailing List
https://usn.ubuntu.com/4251-1/
Third Party Advisory