Lucene search

K
f5F5F5:K13184144
HistoryOct 10, 2019 - 12:00 a.m.

K13184144 : Apache Tomcat vulnerability CVE-2019-0221

2019-10-1000:00:00
my.f5.com
51

6.4 Medium

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.5%

Security Advisory Description

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website. (CVE-2019-0221)

Impact

An attacker may be able to exploit this vulnerability to perform a cross-site scripting (XSS) attack.