CVE Feed

    Dashboard / CVE / CVE-2019-12409

    CVE-2019-12409

    The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.

    Published:Nov 18, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 18, 2019
    EPSS Score:0.8277
    CVSS Score:9.8

    Affected Products

    Vendor
    Apache
    Product
    Solr
    Vendor
    Linux
    Product
    Linux Kernel

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High