peter bassill · operator
$ cve CVE-2019-0192 JSON

CVE-2019-0192

9.8
CRITICAL · CVSS 3.0 · EPSS 77.5% (pctl 100)

Patch early

EPSS 77.5% — above the 10% action threshold.

Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS77.51% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2019-03-07
Last modified2026-06-17

Affected (2)

VendorProduct
apachesolr
netappstorage automation store

References

→ the Explorer  ·  watch your stack  ·  NVD