SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0221

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS.

MEDIUM 6.1EPSS 45.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 45.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
45.57% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
apache/tomcat
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.