Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Mageia: 2020-0054 Critical: Tomcat RMI Registry Credential Theft

mageia
Calendar Grey January 28, 2020
Dist Mageia Esm H88
Newly released Tomcat updates address severe security vulnerabilities in Mageia that impact access to the JMX interface. For further information, click here.
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process...

Summary

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance. (CVE-2019-12418)
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability. (CVE-2019-17563)

References

- https://bugs.mageia.org/show_bug.cgi?id=25987

- https://lists.debian.org/debian-security-announce/2019/msg00250.html

- https://tomcat.apache.org/security-9.html

- https://tomcat.apache.org/security-9.html

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QKC3AMZQVWY34PC24RYAAO4N57HWS6QG/

- http://lists.suse.com/pipermail/sle-security-updates/2020-January/006307.html

- https://www.cve.org/CVERecord?id=CVE-2019-12418

- https://www.cve.org/CVERecord?id=CVE-2019-17563

Resolution

SRPMS

- 7/core/tomcat-9.0.30-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0054.html
Type: security
CVE: CVE-2019-12418, CVE-2019-17563

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here