Security Advisory

CVE-2019-10104

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-07-03 18:52:13
Last updated 2024-08-04 22:10:09
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.