PT-2019-5229 · Apache+3 · Apache Tomcat+3

Published

2019-11-14

·

Updated

2024-06-15

·

CVE-2019-12418

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.28 Apache Tomcat versions 8.5.0 through 8.5.47 Apache Tomcat version 7.0.0 Apache Tomcat version 7.0.97
Description The issue is related to the JMX Remote Lifecycle Listener in Apache Tomcat, which can be exploited by a local attacker to perform a man-in-the-middle attack and capture user names and passwords used to access the JMX interface. This can lead to unauthorized access to the JMX interface and complete control over the Tomcat instance. The vulnerability is due to a lack of protection for registration data.
Recommendations For Apache Tomcat versions 9.0.0.M1 through 9.0.28, consider disabling the JMX Remote Lifecycle Listener until a patch is available. For Apache Tomcat versions 8.5.0 through 8.5.47, consider disabling the JMX Remote Lifecycle Listener until a patch is available. For Apache Tomcat version 7.0.0, consider disabling the JMX Remote Lifecycle Listener until a patch is available. For Apache Tomcat version 7.0.97, consider disabling the JMX Remote Lifecycle Listener until a patch is available. As a temporary workaround, restrict access to the JMX interface to minimize the risk of exploitation.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2892
ALT-PU-2020-3213
ALT-PU-2021-2858
BDU:2020-01972
CVE-2019-12418
DLA-2077-1
DLA-2155-1
DSA-4596-1
DSA-4680-1
GHSA-HH3J-X4MC-G48R
MGASA-2020-0054
OPENSUSE-SU-2020:0038-1
OPENSUSE-SU-2020_0038-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2020:0861
RHSA-2020:1520
SUSE-SU-2020:0029-1
SUSE-SU-2020:0226-1
SUSE-SU-2020:0632-1
SUSE-SU-2020:14375-1
SUSE-SU-2020:1497-1
SUSE-SU-2020:1498-1
SUSE-SU-2020_1497-1
SUSE-SU-2020_1498-1
USN-4251-1

Affected Products

Alt Linux
Apache Tomcat
Suse
Ubuntu