VDB

CVE-2019-9186

CVE-2019-9186 PUBLISHED

In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when the configuration is running, because a JMX server listens on all interfaces (instead of listening on only the localhost interface). This issue has been fixed in the following versions: 2019.1, 2018.3.4, 2018.2.8, 2018.1.8, and 2017.3.7.

EPSS 0.03% · 8.0th percentile

Risk Scores

EPSS Score
0.03%
8.0th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSintellij-community-idea183.5153.4-4, 0, 183.5153.4-3
Ubuntu:25.10intellij-community-idea183.5153.4-6, 0, 183.5153.4-5
Ubuntu:22.04:LTSintellij-community-idea0, 183.5153.4-2

Timeline

  • Jul 3, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›