Record summary

CVE-2019-0221 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE ListApache Tomcat 9.0.0.M1 to 9.0.0.17affected
8.5.0 to 8.5.39affected
7.0.0 to 7.0.93affected

org.apache.tomcat.embed:tomcat-embed-core

Browse Maven / org.apache.tomcat.embed:tomcat-embed-core
GitHub Advisory9.0.0 to < 9.0.17 · Fixed in 9.0.17affected
8.5.0 to < 8.5.40 · Fixed in 8.5.40affected
7.0.0 to < 7.0.94 · Fixed in 7.0.94affected
GitHub Advisory9.0.0 to < 9.0.17 · Fixed in 9.0.17affected
8.5.0 to < 8.5.40 · Fixed in 8.5.40affected
7.0.0 to < 7.0.94 · Fixed in 7.0.94affected

org.apache.tomcat:tomcat-catalina

Browse Maven / org.apache.tomcat:tomcat-catalina
GitHub Advisory9.0.0 to < 9.0.17 · Fixed in 9.0.17affected
8.5.0 to < 8.5.40 · Fixed in 8.5.40affected
7.0.0 to < 7.0.94 · Fixed in 7.0.94affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)ExploitDB exploitby Central InfoSecNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMApache Tomcat - Cross-Site ScriptingCVSS 6.1

Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39, and 7.0.0 to 7.0.93 are vulnerable to cross-site scripting because the SSI printenv command echoes user provided data without escaping. Note: SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Apply the necessary patches or updates provided by Apache Tomcat to fix the XSS vulnerability.

WeaknessesCWE-79
Authorspikpikcu
Template tagscve2019cveapachexsstomcatseclistsedbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Shodan: title:"Apache Tomcat"
Shodan: http.title:"apache tomcat"
Shodan: http.html:"apache tomcat"
Shodan: cpe:"cpe:2.3:a:apache:tomcat"
FOFA: body="apache tomcat"
FOFA: title="apache tomcat"
Google: intitle:"apache tomcat"

Source: ProjectDiscovery

References

Showing 12 of 47