GHSA-hh3j-x4mc-g48r · Severity: high · Ecosystem: maven — Insufficiently Protected Credentials in Apache Tomcat
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Conclusion & alert: CVE-2019-12418 is rated Moderate Risk (51.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.22%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.48% | 1.22% | +0.74% |
| 2 | 2026-05-29 | 0.36% | 0.48% | +0.13% |
| 3 | 2026-05-26 | — | 0.36% | — |
Full EPSS history (48 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.0 | 3.1 | HIGH |
|
1.0 | 5.9 | [email protected] |
| 4.4 | 2.0 | MEDIUM |
|
3.4 | 6.4 | [email protected] |
GHSA-hh3j-x4mc-g48r · Severity: high · Ecosystem: maven — Insufficiently Protected Credentials in Apache Tomcat
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-12418 not yet assigned priority: Debian including 1 source packages (tomcat9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-12418 |
gentoo
|
normal | CVE-2019-12418: 1 GLSA(s) (202003-43), 1 atom(s) (www-servers/tomcat); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2019-12418 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-12418 |
suse
|
high | CVE-2019-12418 severity important: SUSE including 342 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 535 product×package rows across 32 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 5, … (32 product lines)): Fixed 290, Known Affected 231, Known Not Affected 14. | https://www.suse.com/security/cve/CVE-2019-12418/ |
ubuntu
|
medium | CVE-2019-12418 medium priority: Ubuntu including 3 source packages (tomcat7, tomcat8, tomcat9), 54 status rows across 18 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 31, not-affected 12, needed 5, released 4, ignored 2. | https://ubuntu.com/security/CVE-2019-12418 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | tomcat | >= 7.0.0, <= 7.0.97 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomcat | >= 8.5.0, <= 8.5.47 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomcat | >= 9.0.0, <= 9.0.28 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| oracle | workload_manager | 12.2.0.1 | cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:* |
| oracle | workload_manager | 18c | cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:* |
| oracle | workload_manager | 19c | cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| netapp | oncommand_system_manager | >= 3.0.0, <= 3.1.3 | cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* |