CVE-2019-0232

Scores

EPSS

0.941high94.1%
0%20%40%60%80%100%

Percentile: 94.1%

CVSS

5.9medium3.x
0246810

CVSS Score: 5.9/10

All CVSS Scores

CVSS 3.x
5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange’s blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

debiannvdredhatubuntu

CWEs

CWE-20CWE-78

Related Vulnerabilities

Exploits

Exploit ID: 47073

Source: exploitdb

URL: https://www.exploit-db.com/exploits/47073

Exploit ID: CVE-2019-0232

Source: github-poc

URL: https://github.com/r4vl1t0/CVE-2019-0232

Vulnerable Software (33)

Type: Configuration

Product: jws5-ecj

Operating System: rhel

Trait:
{  "fixed": "4.12.0-1.redhat_1.1.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-ecj

Operating System: rhel

Trait:
{  "fixed": "4.12.0-1.redhat_1.1.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-ecj

Operating System: rhel

Trait:
{  "fixed": "4.12.0-1.redhat_1.1.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-javapackages-tools

Operating System: rhel

Trait:
{  "fixed": "3.4.1-5.15.11.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-javapackages-tools

Operating System: rhel

Trait:
{  "fixed": "3.4.1-5.15.11.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-javapackages-tools

Operating System: rhel

Trait:
{  "fixed": "3.4.1-5.15.11.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-jboss-logging

Operating System: rhel

Trait:
{  "fixed": "3.3.2-1.Final_redhat_00001.1.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-jboss-logging

Operating System: rhel

Trait:
{  "fixed": "3.3.2-1.Final_redhat_00001.1.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-jboss-logging

Operating System: rhel

Trait:
{  "fixed": "3.3.2-1.Final_redhat_00001.1.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-mod_cluster

Operating System: rhel

Trait:
{  "fixed": "1.4.1-1.Final_redhat_00001.2.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-mod_cluster

Operating System: rhel

Trait:
{  "fixed": "1.4.1-1.Final_redhat_00001.2.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-mod_cluster

Operating System: rhel

Trait:
{  "fixed": "1.4.1-1.Final_redhat_00001.2.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat

Operating System: rhel

Trait:
{  "fixed": "9.0.21-10.redhat_4.1.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat

Operating System: rhel

Trait:
{  "fixed": "9.0.21-10.redhat_4.1.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat

Operating System: rhel

Trait:
{  "fixed": "9.0.21-10.redhat_4.1.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat-native

Operating System: rhel

Trait:
{  "fixed": "1.2.21-34.redhat_34.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat-native

Operating System: rhel

Trait:
{  "fixed": "1.2.21-34.redhat_34.el7jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat-native

Operating System: rhel

Trait:
{  "fixed": "1.2.21-34.redhat_34.el8jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat-vault

Operating System: rhel

Trait:
{  "fixed": "1.1.8-1.Final_redhat_1.1.el6jws"}

Source: redhat

Type: Configuration

Product: jws5-tomcat-vault

Operating System: rhel

Trait:
{  "fixed": "1.1.8-1.Final_redhat_1.1.el7jws"}

Source: redhat