CyberSec.Space Logo
Back to CVE Browser

CVE-2019-9186

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1880%
EPSS Percentile21.02th
PublishedJul 3, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

Affected Platforms (CPE)

πŸ“¦
Jetbrains

Intellij Idea

>= 2018.1 and < 2018.1.8
πŸ“¦
Jetbrains

Intellij Idea

>= 2018.2 and < 2018.2.8
πŸ“¦
Jetbrains

Intellij Idea

>= 2018.3 and < 2018.3.5
πŸ“¦
Jetbrains

Intellij Idea

>= 2018.3.6 and < 2019.1

References & Advisories

Related Vulnerabilities