logo

Apache Tomcat JMX Risks Explained

ID: aacabca2-917a-51e9-942c-2480f6cc09a4

STIX ID: report--aacabca2-917a-51e9-942c-2480f6cc09a4

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-08-03

...
...

This blog post details how exposing Tomcat's JMX service can lead to full server compromise: it shows how attackers can read manager credentials via MBeans, abuse the AccessLogValve.rotate operation to create JSP web shells for remote command execution, enumerate session IDs to hijack users, capture SMB challenge-responses, and brute-force JMX authentication; the author provides proof-of-concept steps, tools, and mitigations (firewalling, strong auth/SSL, restricting rotate behavior, hashing manager passwords).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.