CVE-2019-0192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
07/03/2019
Last modified:
07/11/2023

Description

In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* 5.0.0 (including) 5.5.5 (including)
cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* 6.0.0 (including) 6.6.5 (including)
cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*