PT-2019-4683 · Apache+3 · Apache Tomcat+3
Published
2019-04-12
·
Updated
2024-07-23
·
CVE-2019-0221
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 7.0.0 through 7.0.93
Apache Tomcat versions 8.5.0 through 8.5.39
Apache Tomcat versions 9.0.0.M1 through 9.0.0.17
Description
The issue is related to the SSI printenv command in Apache Tomcat, which echoes user-provided data without escaping, making it vulnerable to cross-site scripting (XSS) attacks. This command is intended for debugging purposes and is unlikely to be present in a production website. SSI is disabled by default.
Recommendations
For Apache Tomcat versions 7.0.0 through 7.0.93, consider disabling the SSI printenv command as a temporary workaround until a patch is available.
For Apache Tomcat versions 8.5.0 through 8.5.39, consider disabling the SSI printenv command as a temporary workaround until a patch is available.
For Apache Tomcat versions 9.0.0.M1 through 9.0.0.17, consider disabling the SSI printenv command as a temporary workaround until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Tomcat
Suse
Ubuntu