CVE-2019-0192 Vulnerability Details

  /     /     /  

CVE-2019-0192 Metadata Quick Info

CVE Published: 07/03/2019 | CVE Updated: 16/09/2024 | CVE Year: 2019
Source: apache | Vendor: Apache Software Foundation | Product: Apache Solr
Status : PUBLISHED

CVE-2019-0192 Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr\'s unsafe deserialization to trigger remote code execution on the Solr side.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Deserialization of Untrusted Data
Source: Apache Software Foundation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).