Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-0221

Severity
6.1MEDIUM
EPSS
19.3%
top 4.63%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 28
Latest updateJul 23

Description

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages7 packages

NVDapache/tomcat7.0.07.0.93+3
CVEListV5apache/apache_tomcat7.0.0 to 7.0.93, 8.5.0 to 8.5.39, Apache Tomcat 9.0.0.M1 to 9.0.0.17+2
Debiantomcat9< 9.0.16-4+3
Ubuntutomcat8< 8.0.32-1ubuntu1.10+1

🔴Vulnerability Details

7
OSV
tomcat vulnerabilities2024-07-23
OSV
tomcat9 vulnerabilities2019-09-18
OSV
tomcat8 vulnerabilities2019-09-10
GHSA
Cross-site scripting in Apache Tomcat2019-05-30
OSV
Cross-site scripting in Apache Tomcat2019-05-30

💥Exploits & PoCs

2
Exploit-DB
Apache Tomcat 9.0.0.M1 - Cross-Site Scripting (XSS)2021-07-13
Nuclei
Apache Tomcat - Cross-Site Scripting

📋Vendor Advisories

7
Ubuntu
Tomcat vulnerabilities2024-07-23
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Platform Security (Apache Tomcat) — CVE-2019-02212021-04-15
Ubuntu
Tomcat vulnerabilities2019-09-18
Ubuntu
Tomcat vulnerabilities2019-09-10
Red Hat
tomcat: XSS in SSI printenv2019-04-13

💬Community

3
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv2019-05-23
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv [epel-all]2019-05-23
Bugzilla
CVE-2019-0221 tomcat: XSS in SSI printenv [fedora-all]2019-05-23