CVE-2019-0221
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
- Affected products
- Alt Linux, Apache Tomcat, Suse, Ubuntu
- Apache Tomcat
- ≤ 7.0.93, 8.5.39, 9.0.17, 9.0.0
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 45.6% (99th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2019-05-28
CVE-2019-0221 at NVD
3 known exploits for CVE-2019-0221
Proof-of-concept code and exploit modules indexed by Sploitus