CVE-2019-12418: Apache Tomcat
High severity, CVSS 7.0. EPSS: 1.2% chance of exploitation in the next 30 days.
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Affected products
- Apache Tomcat: from 7.0.0, up to and including 7.0.97; from 8.5.0, up to and including 8.5.47; from 9.0.0, up to and including 9.0.28
- Canonical Ubuntu Linux: version 16.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Netapp Oncommand System Manager: from 3.0.0, up to and including 3.1.3
- Opensuse Leap: version 15.1 only
- Oracle Workload Manager: version 12.2.0.1 only; version 18c only; version 19c only
Published 2019-12-23. Last modified 2026-10-08.