CVE-2019-0232
87Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actepss 100%
da publicação à arma0 dias
Publicada no NVD15 de abr.
1ª PoC15 de abr.
metasploit10 de abr.
VulnCheck+728d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simVulnCheck
28 exploit(s) público(s)
O que os fabricantes declaram (VEX)
Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.
Red Hatdocumento VEX ↗
Afetado
1 produto (14 componentes)
Red Hat JBoss Enterprise Web Server 2
no_fix_planned: Will not fix
Corrigido
4 produtos (84 componentes)
Red Hat JBoss Web Server 5.2 for RHEL 6 Server · Red Hat JBoss Web Server 5.2 for RHEL 7 Server · Red Hat JBoss Web Server 5.2 for RHEL 8 · Red Hat JBoss Web Server 3.1
Não afetado
18 produtos (42 componentes) — porque o código vulnerável não está presente no produto
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat Software Collections · Red Hat BPM Suite 6 · Red Hat Enterprise Linux 8 · e outros 13
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).
Produtos afetados
Apache · TomcatPoCs públicas encontradas — 28✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47073githubgithub.com/pyn3rd/CVE-2019-0232★ 190githubgithub.com/jas502n/CVE-2019-0232★ 82githubgithub.com/jaiguptanick/CVE-2019-0232★ 33githubgithub.com/setrus/CVE-2019-0232★ 20githubgithub.com/cyy95/CVE-2019-0232-EXP★ 3githubgithub.com/Dharan10/CVE-2019-0232★ 2githubgithub.com/Nicoslo/Windows-exploitation-Apache-Tomcat-8.5.19-CVE-2019-0232-★ 1githubgithub.com/yuzuki-ayanami/CVE-2019-0232★ 1githubgithub.com/Nicoslo/Windows-Exploitation-Web-Server-Tomcat-8.5.39-CVE-2019-0232★ 1githubgithub.com/Jorge2Rubio/CVE-2019-0232★ 1githubgithub.com/xsxtw/CVE-2019-0232★ 0githubgithub.com/x3m1Sec/CVE-2019-0232_tomcat_cgi_exploit★ 0githubgithub.com/r4vl1t0/CVE-2019-0232★ 0githubgithub.com/blackjuker2/CVE-2019-0232★ 0githubgithub.com/luongchivi/Preproduce-CVE-2019-0232★ 0vulncheckvulncheck.com/xdb/8e3423645344não verificadovulncheckvulncheck.com/xdb/775149bbfff6não verificadovulncheckvulncheck.com/xdb/67571ae1c53cnão verificadovulncheckvulncheck.com/xdb/783921b65e93não verificadovulncheckvulncheck.com/xdb/02fb524c7dabnão verificadovulncheckvulncheck.com/xdb/76c88b02d504não verificadovulncheckvulncheck.com/xdb/8f307d19fb1fnão verificadovulncheckvulncheck.com/xdb/ba258a523b54não verificadovulncheckvulncheck.com/xdb/8c80fe963342não verificadovulncheckvulncheck.com/xdb/510633c31536não verificadovulncheckvulncheck.com/xdb/c78c5341fccfnão verificadocve_referencepacketstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://packetstormsecurity.com/files/153506/Apache-Tomcat-CGIServlet-enableCmdLineArguments-Remote-Code-Execution.htmlhttps://access.redhat.com/errata/RHSA-2019:1712https://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-cve-2019-0232-a-remote-code-execution-vulnerability-in-apache-tomcat/https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.htmlhttp://seclists.org/fulldisclosure/2019/May/4https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3%40%3Cnotifications.ofbiz.apache.org%3E