Vulnerability Details CVE-2019-0193
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.936
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 9.0
Proposed Action
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
Ransomware Campaign
Unknown
Products affected by CVE-2019-0193
-
-
cpe:2.3:a:apache:solr:1.1.0
-
cpe:2.3:a:apache:solr:1.2
-
cpe:2.3:a:apache:solr:1.2.0
-
cpe:2.3:a:apache:solr:1.3.0
-
cpe:2.3:a:apache:solr:1.4.0
-
cpe:2.3:a:apache:solr:1.4.1
-
cpe:2.3:a:apache:solr:3.1
-
cpe:2.3:a:apache:solr:3.1.0
-
cpe:2.3:a:apache:solr:3.2
-
cpe:2.3:a:apache:solr:3.2.0
-
cpe:2.3:a:apache:solr:3.3
-
cpe:2.3:a:apache:solr:3.3.0
-
cpe:2.3:a:apache:solr:3.4.0
-
cpe:2.3:a:apache:solr:3.5.0
-
cpe:2.3:a:apache:solr:3.6.0
-
cpe:2.3:a:apache:solr:3.6.1
-
cpe:2.3:a:apache:solr:3.6.2
-
cpe:2.3:a:apache:solr:4.0.0
-
cpe:2.3:a:apache:solr:4.1.0
-
cpe:2.3:a:apache:solr:4.10.0
-
cpe:2.3:a:apache:solr:4.10.1
-
cpe:2.3:a:apache:solr:4.10.2
-
cpe:2.3:a:apache:solr:4.10.3
-
cpe:2.3:a:apache:solr:4.10.4
-
cpe:2.3:a:apache:solr:4.2.0
-
cpe:2.3:a:apache:solr:4.2.1
-
cpe:2.3:a:apache:solr:4.3.0
-
cpe:2.3:a:apache:solr:4.3.1
-
cpe:2.3:a:apache:solr:4.4.0
-
cpe:2.3:a:apache:solr:4.5.0
-
cpe:2.3:a:apache:solr:4.5.1
-
cpe:2.3:a:apache:solr:4.6.0
-
cpe:2.3:a:apache:solr:4.6.1
-
cpe:2.3:a:apache:solr:4.7.0
-
cpe:2.3:a:apache:solr:4.7.1
-
cpe:2.3:a:apache:solr:4.7.2
-
cpe:2.3:a:apache:solr:4.8.0
-
cpe:2.3:a:apache:solr:4.8.1
-
cpe:2.3:a:apache:solr:4.9.0
-
cpe:2.3:a:apache:solr:4.9.1
-
cpe:2.3:a:apache:solr:5.0
-
cpe:2.3:a:apache:solr:5.0.0
-
cpe:2.3:a:apache:solr:5.1
-
cpe:2.3:a:apache:solr:5.1.0
-
cpe:2.3:a:apache:solr:5.2.0
-
cpe:2.3:a:apache:solr:5.2.1
-
cpe:2.3:a:apache:solr:5.3
-
cpe:2.3:a:apache:solr:5.3.0
-
cpe:2.3:a:apache:solr:5.3.1
-
cpe:2.3:a:apache:solr:5.3.2
-
cpe:2.3:a:apache:solr:5.4.0
-
cpe:2.3:a:apache:solr:5.4.1
-
cpe:2.3:a:apache:solr:5.5.0
-
cpe:2.3:a:apache:solr:5.5.1
-
cpe:2.3:a:apache:solr:5.5.2
-
cpe:2.3:a:apache:solr:5.5.3
-
cpe:2.3:a:apache:solr:5.5.4
-
cpe:2.3:a:apache:solr:5.5.5
-
cpe:2.3:a:apache:solr:6.0.0
-
cpe:2.3:a:apache:solr:6.0.1
-
cpe:2.3:a:apache:solr:6.1.0
-
cpe:2.3:a:apache:solr:6.2.0
-
cpe:2.3:a:apache:solr:6.2.1
-
cpe:2.3:a:apache:solr:6.3.0
-
cpe:2.3:a:apache:solr:6.4.0
-
cpe:2.3:a:apache:solr:6.4.1
-
cpe:2.3:a:apache:solr:6.4.2
-
cpe:2.3:a:apache:solr:6.5.0
-
cpe:2.3:a:apache:solr:6.5.1
-
cpe:2.3:a:apache:solr:6.6.0
-
cpe:2.3:a:apache:solr:6.6.1
-
cpe:2.3:a:apache:solr:6.6.2
-
cpe:2.3:a:apache:solr:6.6.3
-
cpe:2.3:a:apache:solr:6.6.4
-
cpe:2.3:a:apache:solr:6.6.5
-
cpe:2.3:a:apache:solr:6.6.6
-
cpe:2.3:a:apache:solr:7.0.0
-
cpe:2.3:a:apache:solr:7.0.1
-
cpe:2.3:a:apache:solr:7.1.0
-
cpe:2.3:a:apache:solr:7.2.0
-
cpe:2.3:a:apache:solr:7.2.1
-
cpe:2.3:a:apache:solr:7.3.0
-
cpe:2.3:a:apache:solr:7.3.1
-
cpe:2.3:a:apache:solr:7.4.0
-
cpe:2.3:a:apache:solr:7.5.0
-
cpe:2.3:a:apache:solr:7.6.0
-
cpe:2.3:a:apache:solr:7.7.0
-
cpe:2.3:a:apache:solr:7.7.1
-
cpe:2.3:a:apache:solr:7.7.2
-
cpe:2.3:a:apache:solr:8.1.0
-
cpe:2.3:a:apache:solr:8.1.1
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0