CVE-2019-10104
9.8
CRITICAL · CVSS 3.0 · EPSS 3.8% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.81% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2019-07-03 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| jetbrains | intellij idea |
References
→ the Explorer · watch your stack · NVD