CRITICAL
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only
Published Jul 3, 2019
9.8
CRITICALCVSS 3.0
EPSS 3.81%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.