CVE-2019-10104: JetBrains Intellij Idea
Critical severity, CVSS 9.8. EPSS: 3.8% chance of exploitation in the next 30 days.
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Affected products
- JetBrains Intellij Idea: from 2018.1, before 2018.1.8 (fixed in 2018.1.8); from 2018.2, before 2018.2.8 (fixed in 2018.2.8); from 2018.3, before 2018.3.4 (fixed in 2018.3.4); from 2018.3.5, before 2018.3.7 (fixed in 2018.3.7)
Published 2019-07-03. Last modified 2026-06-17.