High severity7.0NVD Advisory· Published Dec 23, 2019· Updated Jun 17, 2026
CVE-2019-12418
CVE-2019-12418
Description
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat.embed:tomcat-embed-coreMaven | < 7.0.99 | 7.0.99 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 8.0.0, < 8.5.49 | 8.5.49 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 9.0.0, < 9.0.29 | 9.0.29 |
Affected products
37- cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*Range: >=3.0.0,<=3.1.3
cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- osv-coords26 versionspkg:apk/chainguard/spark-3.5.0-compatpkg:maven/org.apache.tomcat.embed/tomcat-embed-corepkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tomcat&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/tomcat&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP1pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/tomcat&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/tomcat&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/tomcat6&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS
< 3.5.0-r2+ 25 more
- (no CPE)range: < 3.5.0-r2
- (no CPE)range: < 7.0.99
- (no CPE)range: < 9.0.30-lp151.3.6.1
- (no CPE)range: < 9.0.36-8.4
- (no CPE)range: < 10.1.14-1.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 9.0.30-3.34.1
- (no CPE)range: < 9.0.30-4.10.1
- (no CPE)range: < 8.0.53-10.43.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 9.0.31-3.25.1
- (no CPE)range: < 9.0.31-3.25.1
- (no CPE)range: < 8.0.53-10.43.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 9.0.31-3.25.1
- (no CPE)range: < 9.0.31-3.25.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 8.0.53-29.27.1
- (no CPE)range: < 6.0.53-0.57.16.1
- (no CPE)range: < 6.0.53-0.57.16.1
- Apache Software Foundation/Apache Tomcatv5Range: 9.0.0.M1 to 9.0.28
Patches
Vulnerability mechanics
References
27- www.oracle.com/security-alerts/cpuapr2020.htmlnvdPatchThird Party AdvisoryWEB
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.htmlnvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-hh3j-x4mc-g48rghsaADVISORY
- lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/01/msg00024.htmlnvdMailing ListThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2020/03/msg00029.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-12418ghsaADVISORY
- seclists.org/bugtraq/2019/Dec/43nvdMailing ListThird Party AdvisoryWEB
- security.gentoo.org/glsa/202003-43nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20200107-0001/nvdThird Party Advisory
- usn.ubuntu.com/4251-1/nvdThird Party Advisory
- www.debian.org/security/2019/dsa-4596nvdThird Party AdvisoryWEB
- www.debian.org/security/2020/dsa-4680nvdThird Party AdvisoryWEB
- lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3EghsaWEB
- lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20200107-0001ghsaWEB
- support.f5.com/csp/article/K10107360ghsaWEB
- usn.ubuntu.com/4251-1ghsaWEB
- lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Envd
- lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Envd
- support.f5.com/csp/article/K10107360nvd
News mentions
0No linked articles in our index yet.