CVE-2019-10097

HIGH EXPLOITED

Apache HTTP Server 2.4.32-2.4.39 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-10097 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

References (17)

Core 17
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4126
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujul2020.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html

Scores

CVSS v3 7.2
EPSS 0.2355
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2022-02-22
CWE
CWE-476 CWE-787
Status published
Products (20)
apache/http_server 2.4.33
apache/http_server 2.4.34
apache/http_server 2.4.35
apache/http_server 2.4.37
apache/http_server 2.4.38
oracle/communications_element_manager 8.0.0
oracle/communications_element_manager 8.1.0
oracle/communications_element_manager 8.1.1
oracle/communications_element_manager 8.2.0
oracle/communications_session_report_manager 8.1.1
... and 10 more
Published Sep 26, 2019
Tracked Since Feb 18, 2026