V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-12409
DEB
CriticalConfirmedExploit available

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default …

CVSS
9.1
Critical
EPSS
0.22
p97
Published
2019-01-01
Updated
2019-01-01
Description

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.

Tags · CWE
Pre-authFile upload
CWE-306
CWE-434
CAPEC-1
CAPEC-12
CAPEC-36
CAPEC-62
CAPEC-166
CAPEC-216
Affected products
Lucene-solrLucene-solrLucene-solrLucene-solrLucene-solrLucene-solrSolr
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.219 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
CVE-2019-12409
github-poc · https://github.com/mbadanoiu/CVE-2019-12409
Enterprise
Affected products
ProductVendorStatus
lucene-solrTracked
lucene-solrTracked
lucene-solrTracked
lucene-solrTracked
lucene-solrTracked
lucene-solrTracked
solr*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities