DEBIAN-CVE-2019-12418
Advisory lineage Upstream: 1 Downstream: 4
Upstream
Downstream
Published: 23 Dec 2019, 18:15
Last modified:28 Apr 2026, 20:20
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
7 HIGH
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Dec 2019, 18:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:20
Last Modified
Vulnerability information updated
Description
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- debian•tomcat9
< 9.0.31-1 | < 9.0.31-1 | < 9.0.31-1 | < 9.0.31-1