CVE-2019-12418
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
- Affected products
- Alt Linux, Apache Tomcat, Suse, Ubuntu
- Apache Tomcat
- ≤ 7.0.97, 8.5.47, 9.0.28
- Fix
- Available
- CVSS 3.1
- 7.0 HIGH
- EPSS
- 1.2% (66th percentile)
- NVD status
- Modified
- Published
- 2019-12-23
CVE-2019-12418 at NVD
No indexed exploits for CVE-2019-12418 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-12418 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.