cbcvebase.
CVE-2019-10097
published 2019-09-26

CVE-2019-10097: In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially…

high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

Affected

21 ranges
VendorProductVersion rangeFixed in
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
apachehttp_server
debianapache2< apache2 2.4.41-1 (bookworm)apache2 2.4.41-1 (bookworm)
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oracleenterprise_manager_ops_center
oracleenterprise_manager_ops_center
oraclehttp_server
oracleinstantis_enterprisetrack17.1 – 17.3
oracleretail_xstore_point_of_service

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.2HIGH
vulncheck7.2HIGH