Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-0221

Опубликовано: 13 апр. 2019
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Меры по смягчению последствий

SSI is disabled in the default Tomcat configuration. The vulnerable printenv command is intended for debugging, and is recommended to not be enabled for a production website.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6tomcatOut of support scope
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatAffected
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-containerFix deferred
Red Hat Fuse 7tomcatNot affected
Red Hat JBoss BRMS 5jbosswebOut of support scope
Red Hat JBoss BRMS 6tomcatOut of support scope
Red Hat JBoss Data Grid 6jbosswebOut of support scope
Red Hat JBoss Data Grid 7tomcatNot affected
Red Hat JBoss Data Virtualization 6jbosswebOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79

EPSS

Процентиль: 92%
0.09193
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

CVSS3: 6.1
nvd
около 6 лет назад

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

CVSS3: 6.1
debian
около 6 лет назад

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 ...

CVSS3: 6.1
github
около 6 лет назад

Cross-site scripting in Apache Tomcat

CVSS3: 6.1
fstec
около 6 лет назад

Уязвимость команды printenv сервера приложений Apache Tomcat, позволяющая нарушителю осуществить межсайтовую сценарную атаку

EPSS

Процентиль: 92%
0.09193
Низкий

5 Medium

CVSS3