Get real-time updates on Telegram
CVE-2019-12418: tomcat from 7.0.0 (inclusive), through 7.0.97 (inclusive), from 8.5.0 (inclusive), through 8.5.47 (inclusive), from…
CVE-2019-12418. CVSS 3.1 base score 7.0 (HIGH, NVD). EPSS 0.01221 (percentile 0.67808), scored 2026-10-08.
Affected technology
tomcat · from 7.0.0 (inclusive), through 7.0.97 (inclusive)
apache
tomcat · from 8.5.0 (inclusive), through 8.5.47 (inclusive)
apache
tomcat · from 9.0.0 (inclusive), through 9.0.28 (inclusive)
apache
debian linux · 8.0
debian
debian linux · 9.0
debian
debian linux · 10.0
debian
workload manager · 12.2.0.1
oracle
workload manager · 18c
oracle
workload manager · 19c
oracle
ubuntu linux · 16.04
canonical
leap · 15.1
opensuse
oncommand system manager · from 3.0.0 (inclusive), through 3.1.3 (inclusive)
netapp
Apache Tomcat · 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 to 7.0.97
Apache Software Foundation
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance. NVD’s CVSS 3.1 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high.
- CCR priority
- 28.3 /100 (P4)
- CVSS 3.1
- 7.0 /10 · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.01221 · percentile 0.67808 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2019-12418.html