CVE-2019-0221
published 2019-05-28CVE-2019-0221: The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is…
PriorityP352medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EXPLOIT
EPSS
45.57%
98.7th percentile
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 7.0.0 – 7.0.93 | — |
| apache | tomcat | 8.5.0 – 8.5.39 | — |
| apache | tomcat | 9.0.1 – 9.0.17 | — |
| debian | tomcat9 | < tomcat9 9.0.16-4 (bookworm) | tomcat9 9.0.16-4 (bookworm) |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_apache6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat vulnerabilities
osv·2024-07-23·CVSS 6.1
CVE-2019-0221 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that the Tomcat SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-25329)
OSV
tomcat9 vulnerabilities
osv·2019-09-18·CVSS 7.5
CVE-2019-0221 [HIGH] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that the Tomcat 9 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 9 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
OSV
tomcat8 vulnerabilities
osv·2019-09-10·CVSS 7.5
CVE-2019-0221 [HIGH] tomcat8 vulnerabilities
tomcat8 vulnerabilities
It was discovered that the Tomcat 8 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 8 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
GHSA
Cross-site scripting in Apache Tomcat
ghsa·2019-05-30
CVE-2019-0221 [MEDIUM] CWE-79 Cross-site scripting in Apache Tomcat
Cross-site scripting in Apache Tomcat
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
OSV
Cross-site scripting in Apache Tomcat
osv·2019-05-30
CVE-2019-0221 [MEDIUM] Cross-site scripting in Apache Tomcat
Cross-site scripting in Apache Tomcat
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
OSV
CVE-2019-0221: The SSI printenv command in Apache Tomcat 9
osv·2019-05-28·CVSS 6.1
CVE-2019-0221 [MEDIUM] CVE-2019-0221: The SSI printenv command in Apache Tomcat 9
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-07-23·CVSS 6.1
CVE-2021-25329 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that the Tomcat SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat incorrectly handled certain uncommon
PersistenceManager with FileStore configurations. A remote attacker could
possibly use this issue to execute arbitrary code.
(CVE-2020-9484, CVE-2021-25329)
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) — CVE-2019-0221
vendor_oracle·2021-04-15·CVSS 6.1
CVE-2019-0221 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) — CVE-2019-0221
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) vulnerability
CVE: CVE-2019-0221
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2019-09-18·CVSS 7.5
CVE-2019-0221 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat 9.
It was discovered that the Tomcat 9 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 9 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2019-09-10·CVSS 7.5
CVE-2019-0221 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat 8.
It was discovered that the Tomcat 8 SSI printenv command echoed user
provided data without escaping it. An attacker could possibly use this
issue to perform an XSS attack. (CVE-2019-0221)
It was discovered that Tomcat 8 did not address HTTP/2 connection window
exhaustion on write while addressing CVE-2019-0199. An attacker could
possibly use this issue to cause a denial of service. (CVE-2019-10072)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tomcat: XSS in SSI printenv
vendor_redhat·2019-04-13·CVSS 6.1
CVE-2019-0221 [MEDIUM] CWE-79 tomcat: XSS in SSI printenv
tomcat: XSS in SSI printenv
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Mitigation: SSI is disabled in the default Tomcat configuration. The vulnerable printenv command is intended for debugging, and is recommended to not be enabled for a production website.
Package: tomcat (Red Hat BPM Suite 6) - Out of support scope
Package: tomcat6 (Red Hat Enterprise Linux 6) - Out of support scope
Package: tomcat (Red Hat Enterprise Linux 7) - Fix deferred
Package: pki-deps:10.6/pki-servlet-container (Red Hat Enterprise Linux 8) - Fi
Debian
CVE-2019-0221: tomcat9 - The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 ...
vendor_debian·2019·CVSS 6.1
CVE-2019-0221 [MEDIUM] CVE-2019-0221: tomcat9 - The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 ...
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Scope: local
bookworm: resolved (fixed in 9.0.16-4)
bullseye: resolved (fixed in 9.0.16-4)
forky: resolved (fixed in 9.0.16-4)
sid: resolved (fixed in 9.0.16-4)
trixie: resolved (fixed in 9.0.16-4)
Apache
Apache tomcat: CVE-2019-0221
vendor_apache·CVSS 6.1
CVE-2019-0221 [MEDIUM] Apache tomcat: CVE-2019-0221
Apache tomcat: CVE-2019-0221
The SSI printenv command echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website. This was fixed with commit 4fcdf706 . This issue was identified by Nightwatch Cybersecurity Research and reported to the Apache Tomcat security team via the bug bounty program sponsored by the EU FOSSA-2 project on 7th March 2019. The issue was made public on 17 May 2019. Affects: 8.5.0 to 8.5.39 8 February 2019 Fixed in Apache Tomcat 8.5.38 Important: Denial of Service
No detection rules found.
Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
exploitdb·2021-07-13·CVSS 6.1
CVE-2019-0221 [MEDIUM] Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
---
# Exploit Title: Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)
# Date: 05/21/2019
# Exploit Author: Central InfoSec
# Version: Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39, and 7.0.0 to 7.0.93
# CVE : CVE-2019-0221
# Requirements:
# SSI support must be enabled within Apache Tomcat. SSI support is not enabled by default.
# A file (usually "*.shtml") with the "printenv" SSI directive must exist within the web application.
# The file must be accessible.
# Proof of Concept:
# Install a Java Runtime Environment (JRE)
# Download a vulnerable version of Tomcat and extract the contents
# Modify line 19 of the conf\context.xml file to globally enable privileged context
Context privileged="true">
# Modify conf\web.xml t
Nuclei
Apache Tomcat - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2019-0221 [MEDIUM] Apache Tomcat - Cross-Site Scripting
Apache Tomcat - Cross-Site Scripting
Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39, and 7.0.0 to 7.0.93 are vulnerable to cross-site scripting because the SSI printenv command echoes user provided data without escaping. Note: SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Template:
id: CVE-2019-0221
info:
name: Apache Tomcat - Cross-Site Scripting
author: pikpikcu
severity: medium
description: |
Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39, and 7.0.0 to 7.0.93 are vulnerable to cross-site scripting because the SSI printenv command echoes user provided data without escaping. Note: SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a pro
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
HackerOne
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
hackerone·2020-06-11·CVSS 4.3
[MEDIUM] Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
**Summary:**
There are multiple issues found on ███:
1. ███████/examples/ - Apache Tomcat examples are available for public. Multiple issues - session and cookies manipulation, internals IP disclosure.
2. Error page contains information about Apache Tomcat version
3. Reported Tomcat version is vulnerable. Multiple CVEs - critical, high and medium
**Description:**
1. Examples are available by link: ███████/examples/
2. Information disclosure about Apache Tomcat version
3. Vulnerable version Apache Tomcat/8.5.33
https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Base Score: 9.8 CRITICALVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2019-0232
Base Score
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv
bugzilla·2019-05-23·CVSS 6.1
CVE-2019-0221 [MEDIUM] CVE-2019-0221 tomcat: XSS in SSI printenv
CVE-2019-0221 tomcat: XSS in SSI printenv
The SSI printenv command echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Reference:
http://tomcat.apache.org/security-9.html
Upstream commit:
https://github.com/apache/tomcat/commit/15fcd16
Discussion:
Created tomcat tracking bugs for this issue:
Affects: fedora-all [bug 1713279]
---
Created tomcat tracking bugs for this issue:
Affects: epel-all [bug 1713280]
---
This vulnerability is out of security support scope for the following product:
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
Mitigation:
S
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv [epel-all]
bugzilla·2019-05-23·CVSS 6.1
CVE-2019-0221 [MEDIUM] CVE-2019-0221 tomcat: XSS in SSI printenv [epel-all]
CVE-2019-0221 tomcat: XSS in SSI printenv [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL. While
only
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv [fedora-all]
bugzilla·2019-05-23·CVSS 6.1
CVE-2019-0221 [MEDIUM] CVE-2019-0221 tomcat: XSS in SSI printenv [fedora-all]
CVE-2019-0221 tomcat: XSS in SSI printenv [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
arXiv
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
arxiv_fulltext·2025-10-21
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
Wenjing Dang, Kaixuan Li, Member, IEEE, Sen Chen, Member, IEEE, Zhenwei Zhuo, \ Zhang, Member, IEEE, and Zheli Liu, Member, IEEE
Wenjing Dang and Kaixuan Li contributed equally to this work.
Wenjing Dang and Zhenwei Zhuo are with the College of Intelligence and Computing, Tianjin University, China. Kaixuan Li and Lyuye Zhang are with the Nanyang Technological University, Singapore. Sen Chen (Corresponding author) and Zheli Liu are with the Nankai University, China. (email: [email protected]; [email protected]; [email protected]; [email protected]; [email protected]; [email protected])
## Abstract
The Proof-of-Concept (PoC) for a vulnerability is crucial in validating its existence, m
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.htmlhttp://packetstormsecurity.com/files/163457/Apache-Tomcat-9.0.0.M1-Cross-Site-Scripting.htmlhttp://seclists.org/fulldisclosure/2019/May/50http://www.securityfocus.com/bid/108545https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/05/msg00044.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46/https://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20190606-0001/https://support.f5.com/csp/article/K13184144?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4128-1/https://usn.ubuntu.com/4128-2/https://www.debian.org/security/2019/dsa-4596https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://wwws.nightwatchcybersecurity.com/2019/05/27/xss-in-ssi-printenv-command-apache-tomcat-cve-2019-0221/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00090.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00054.htmlhttp://packetstormsecurity.com/files/163457/Apache-Tomcat-9.0.0.M1-Cross-Site-Scripting.htmlhttp://seclists.org/fulldisclosure/2019/May/50http://www.securityfocus.com/bid/108545https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/05/msg00044.htmlhttps://lists.debian.org/debian-lts-announce/2019/08/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46/https://seclists.org/bugtraq/2019/Dec/43https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20190606-0001/https://support.f5.com/csp/article/K13184144?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4128-1/https://usn.ubuntu.com/4128-2/https://www.debian.org/security/2019/dsa-4596https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://wwws.nightwatchcybersecurity.com/2019/05/27/xss-in-ssi-printenv-command-apache-tomcat-cve-2019-0221/
2019-05-28
Published