VDB

CVE-2019-10104

CVE-2019-10104 PUBLISHED

In several JetBrains IntelliJ IDEA Ultimate versions, an Application Server run configuration (for Tomcat, Jetty, Resin, or CloudBees) with the default setting allowed a remote attacker to execute code when the configuration is running, because a JMX server listened on all interfaces instead of localhost only. The issue has been fixed in the following versions: 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

EPSS 0.02% · 6.2th percentile

Risk Scores

EPSS Score
0.02%
6.2th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSintellij-community-idea0, 183.5153.4-2
Ubuntu:25.10intellij-community-idea0, 183.5153.4-6, 183.5153.4-5
Ubuntu:24.04:LTSintellij-community-idea0, 183.5153.4-4, 183.5153.4-4ubuntu1

Timeline

  • Jul 3, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›