CVE-2019-0232
87Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actepss 99%
de la publicación al arma0 días
Publicada en NVD15 abr
1ª PoC15 abr
metasploit10 abr
VulnCheck+728d
probabilidad de explotación
99%top 1% de las CVE
explotación observada
síVulnCheck
28 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Afectado
1 producto (14 componentes)
Red Hat JBoss Enterprise Web Server 2
no_fix_planned: Will not fix
Corregido
4 productos (84 componentes)
Red Hat JBoss Web Server 5.2 for RHEL 6 Server · Red Hat JBoss Web Server 5.2 for RHEL 7 Server · Red Hat JBoss Web Server 5.2 for RHEL 8 · Red Hat JBoss Web Server 3.1
No afectado
18 productos (42 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat Software Collections · Red Hat BPM Suite 6 · Red Hat Enterprise Linux 8 · y otros 13
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).
Productos afectados
Apache · TomcatPoCs públicas encontradas — 28✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47073githubgithub.com/pyn3rd/CVE-2019-0232★ 190githubgithub.com/jas502n/CVE-2019-0232★ 82githubgithub.com/jaiguptanick/CVE-2019-0232★ 33githubgithub.com/setrus/CVE-2019-0232★ 20githubgithub.com/cyy95/CVE-2019-0232-EXP★ 3githubgithub.com/Dharan10/CVE-2019-0232★ 2githubgithub.com/yuzuki-ayanami/CVE-2019-0232★ 1githubgithub.com/Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-★ 1githubgithub.com/Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232★ 1githubgithub.com/Jorge2Rubio/CVE-2019-0232★ 1githubgithub.com/xsxtw/CVE-2019-0232★ 0githubgithub.com/r4vl1t0/CVE-2019-0232★ 0githubgithub.com/blackjuker2/CVE-2019-0232★ 0githubgithub.com/luongchivi/Preproduce-CVE-2019-0232★ 0githubgithub.com/x3m1Sec/CVE-2019-0232_tomcat_cgi_exploit★ 0vulncheckvulncheck.com/xdb/783921b65e93no verificadovulncheckvulncheck.com/xdb/67571ae1c53cno verificadovulncheckvulncheck.com/xdb/775149bbfff6no verificadovulncheckvulncheck.com/xdb/c78c5341fccfno verificadovulncheckvulncheck.com/xdb/8c80fe963342no verificadovulncheckvulncheck.com/xdb/ba258a523b54no verificadovulncheckvulncheck.com/xdb/8e3423645344no verificadovulncheckvulncheck.com/xdb/510633c31536no verificadovulncheckvulncheck.com/xdb/8f307d19fb1fno verificadovulncheckvulncheck.com/xdb/76c88b02d504no verificadocve_referencepacketstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.htmlno verificadovulncheckvulncheck.com/xdb/02fb524c7dabno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.htmlhttps://access.redhat.com/errata/RHSA-2019:1712https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-cve-2019-0232-a-remote-code-execution-vulnerability-in-apache-tomcat/https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.htmlhttp://seclists.org/fulldisclosure/2019/May/4https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3%40%3Cnotifications.ofbiz.apache.org%3E