CVE-2019-12418
tomcat8 - security update
7.0
HIGH
CVSS 3.1
EPSS 0.48%
Description
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
How to fix CVE-2019-12418
To remediate CVE-2019-12418, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.56-3+really7.0.99-1 or later
- —upgrade to 8.0.14-1+deb8u16 or later
- —upgrade to 9.0.31-1 or later
- —upgrade to 7.0.99 or later
Is CVE-2019-12418 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 7.0.56-3+really7.0.99-1
- from 0, < 8.0.14-1+deb8u16
- from 0, < 9.0.31-1
- from 0, < 7.0.99
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |