CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-10104

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1880%
EPSS Percentile22.07th
Published2019年7月3日
Last Modified2024年11月21日

Vulnerability Description

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

Affected Platforms (CPE)

📦
Jetbrains

Intellij Idea

>= 2018.1 and < 2018.1.8
📦
Jetbrains

Intellij Idea

>= 2018.2 and < 2018.2.8
📦
Jetbrains

Intellij Idea

>= 2018.3 and < 2018.3.4
📦
Jetbrains

Intellij Idea

>= 2018.3.5 and < 2018.3.7

References & Advisories

関連する脆弱性情報