tomcat: local privilege escalation
Published Dec 23, 2019
7.4
HIGHCVSS 3.1
EPSS 1.22%
Description
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Affected products
-
- Version 7.0.0 to 7.0.97StatusaffectedConstraints-
- Version 8.5.0 to 8.5.47StatusaffectedConstraints-
- Version 9.0.0.M1 to 9.0.28StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | n/a |
|
Configuration 1
Configuration 2
- 8.0
- 9.0
- 10.0
Configuration 3
- 12.2.0.1
- 18c
- 19c
Configuration 4
- 16.04
Configuration 6
- ≥ 3.0.0 · ≤ 3.1.3
No data.
Red Hat JBoss Web Server (JWS) 5.3
tomcat
Fixed · RHSA-2020:1521
Red Hat JBoss Web Server 3 for RHEL 6
tomcat-native-0:1.2.23-21.redhat_21.ep7.el6
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3 for RHEL 6
tomcat7-0:7.0.70-38.ep7.el6
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3 for RHEL 6
tomcat8-0:8.0.36-42.ep7.el6
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3 for RHEL 7
tomcat-native-0:1.2.23-21.redhat_21.ep7.el7
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3 for RHEL 7
tomcat7-0:7.0.70-38.ep7.el7
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3 for RHEL 7
tomcat8-0:8.0.36-42.ep7.el7
Fixed · RHSA-2020:0861
Red Hat JBoss Web Server 3.1
tomcat
Fixed · RHSA-2020:0860
Red Hat JBoss Web Server 5.3 on RHEL 6
jws5-tomcat-0:9.0.30-3.redhat_4.1.el6jws
Fixed · RHSA-2020:1520
Red Hat JBoss Web Server 5.3 on RHEL 6
jws5-tomcat-native-0:1.2.23-4.redhat_4.el6jws
Fixed · RHSA-2020:1520
Red Hat JBoss Web Server 5.3 on RHEL 7
jws5-tomcat-0:9.0.30-3.redhat_4.1.el7jws
Fixed · RHSA-2020:1520
Red Hat JBoss Web Server 5.3 on RHEL 7
jws5-tomcat-native-0:1.2.23-4.redhat_4.el7jws
Fixed · RHSA-2020:1520
Red Hat JBoss Web Server 5.3 on RHEL 8
jws5-tomcat-0:9.0.30-3.redhat_4.1.el8jws
Fixed · RHSA-2020:1520
Red Hat JBoss Web Server 5.3 on RHEL 8
jws5-tomcat-native-0:1.2.23-4.redhat_4.el8jws
Fixed · RHSA-2020:1520
Red Hat BPM Suite 6
tomcat
Out of support scope
Red Hat Enterprise Linux 5
tomcat5
Not affected
Red Hat Enterprise Linux 6
tomcat6
Out of support scope
Red Hat Enterprise Linux 7
tomcat
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/pki-servlet-engine
Will not fix
Red Hat Fuse 7
tomcat
Not affected
Red Hat JBoss BRMS 6
tomcat
Out of support scope
Red Hat JBoss Data Grid 7
tomcat
Not affected
Red Hat JBoss Fuse 6
tomcat
Not affected
Red Hat Software Collections
rh-java-common-tomcat
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Web Server (JWS) 5.3 | tomcat | Fixed | RHSA-2020:1521 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat-native-0:1.2.23-21.redhat_21.ep7.el6 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat7-0:7.0.70-38.ep7.el6 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat8-0:8.0.36-42.ep7.el6 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat-native-0:1.2.23-21.redhat_21.ep7.el7 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat7-0:7.0.70-38.ep7.el7 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat8-0:8.0.36-42.ep7.el7 | Fixed | RHSA-2020:0861 |
| Red Hat JBoss Web Server 3.1 | tomcat | Fixed | RHSA-2020:0860 |
| Red Hat JBoss Web Server 5.3 on RHEL 6 | jws5-tomcat-0:9.0.30-3.redhat_4.1.el6jws | Fixed | RHSA-2020:1520 |
| Red Hat JBoss Web Server 5.3 on RHEL 6 | jws5-tomcat-native-0:1.2.23-4.redhat_4.el6jws | Fixed | RHSA-2020:1520 |
| Red Hat JBoss Web Server 5.3 on RHEL 7 | jws5-tomcat-0:9.0.30-3.redhat_4.1.el7jws | Fixed | RHSA-2020:1520 |
| Red Hat JBoss Web Server 5.3 on RHEL 7 | jws5-tomcat-native-0:1.2.23-4.redhat_4.el7jws | Fixed | RHSA-2020:1520 |
| Red Hat JBoss Web Server 5.3 on RHEL 8 | jws5-tomcat-0:9.0.30-3.redhat_4.1.el8jws | Fixed | RHSA-2020:1520 |
| Red Hat JBoss Web Server 5.3 on RHEL 8 | jws5-tomcat-native-0:1.2.23-4.redhat_4.el8jws | Fixed | RHSA-2020:1520 |
| Red Hat BPM Suite 6 | tomcat | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | tomcat5 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | tomcat6 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Will not fix | n/a |
| Red Hat Fuse 7 | tomcat | Not affected | n/a |
| Red Hat JBoss BRMS 6 | tomcat | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | tomcat | Not affected | n/a |
| Red Hat JBoss Fuse 6 | tomcat | Not affected | n/a |
| Red Hat Software Collections | rh-java-common-tomcat | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw did not affect the versions of tomcat as shipped with Red Hat Enterprise Linux 5, as they did not include JMX Remote Lifecycle Listener, which was introduced in a later version of the package. pki-servlet-engine has been obsoleted by Tomcat in Red Hat Enterprise Linux 8.9 and later. Therefore no additional fixes would be made available for the servlet engine.
Red Hat mitigation
Disable JMX Remote if monitoring is only needed locally and there is no need to monitor Tomcat remotely. If JMX Remote is required and cannot be disabled, then use the built-in remote JMX facilities provided by the JVM. Please note that JMX Remote Lifecycle Listener is now deprecated and may be removed from both Tomcat 7 [1] and Tomcat 9 [2] after 2020-12-31. [1] https://tomcat.apache.org/tomcat-7.0-doc/config/listeners.html#Deprecated_Implementations [2] https://tomcat.apache.org/tomcat-9.0-doc/config/listeners.html#Deprecated_Implementations
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.22% (0.01221) | 67.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.22% (0.01221) | 64.65th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.56% (0.00556) | 66.17th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00047) | 19.26th | v3 (v2023.03.01) |
| May 8, 2024 | 0.05% (0.00047) | 16.32th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00047) | 14.30th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.57% (0.04573) | 88.93th | v2 (v2022.01.01) |
| Apr 19, 2022 | 4.57% (0.04573) | 87.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.05% (0.03052) | 82.04th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.56% (0.09558) | 87.16th | v2 (v2022.01.01) |
| Feb 3, 2022 | 21.49% (0.21485) | 94.46th | v1 |
| Jan 6, 2022 | 21.49% (0.21485) | 94.40th | v1 |
| Sep 1, 2021 | 5.75% (0.05748) | 89.02th | v1 |
| Apr 14, 2021 | 5.75% (0.05748) | 0.00th | v1 |
References (32)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00013.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://mail-archives.apache.org/mod_mbox/tomcat-users/201912.mbox/%3C3f42d82c-d9e9-8893-9820-df4e420e5c4e@apache.org%3E
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.49
- http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.29
- https://access.redhat.com/security/cve/CVE-2019-12418 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1785699 Issue Tracking
- https://github.com/advisories/GHSA-hh3j-x4mc-g48r Advisory
- https://lists.apache.org/thread.html/43530b91506e2e0c11cfbe691173f5df8c48f51b98262426d7493b67%40%3Cannounce.tomcat.apache.org%3E x_refsource_CONFIRMMailing ListVendor Advisory
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a@%3Cdev.tomcat.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/01/msg00024.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00029.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-12418
- https://seclists.org/bugtraq/2019/Dec/43 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202003-43 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200107-0001/ x_refsource_CONFIRMThird Party Advisory
- https://support.f5.com/csp/article/K10107360?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://support.f5.com/csp/article/K10107360?utm_source=f5support&utm_medium=RSS
- https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.99
- https://usn.ubuntu.com/4251-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-12418
- https://www.debian.org/security/2019/dsa-4596 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2020/dsa-4680 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.