apache solr CVE-2019-0192 in Apache and NetApp Products
Published on March 7, 2019

product logo product logo
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

Vendor Advisory NVD


Products Associated with CVE-2019-0192

stack.watch emails you whenever new vulnerabilities are published in Apache Solr or NetApp Storage Automation Store. Just hit a watch button to start following.

 
 

Affected Versions

Apache Software Foundation Apache Solr Version Apache Solr 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5 is affected by CVE-2019-0192

Exploit Probability

EPSS
93.46%
Percentile
99.82%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.