U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2019-0232

Change History

Initial Analysis by NIST 4/16/2019 11:20:41 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 7.0.0 up to (including) 7.0.93
          *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (including) 8.5.39
          *cpe:2.3:a:apache:tomcat:9.0.0:m1:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m10:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m11:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m12:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m13:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m14:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m15:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m16:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m17:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m18:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m19:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m2:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m20:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m21:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m22:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m23:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m24:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m25:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m26:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m3:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m4:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m5:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m6:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m7:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m8:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:9.0.0:m9:*:*:*:*:*:*
          *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 9.0.1 up to (including) 9.0.17
     OR
          cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Added CVSS V3

								
							
							
						
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-20
Added Reference

								
							
							
						
https://tools.cisco.com/security/center/viewAlert.x?alertId=60004&vs_f=Alert%20RSS&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Apache%20Tomcat%20CGI%20Servlet%20Arbitrary%20Code%20Execution%20Vulnerability&vs_k=1 [Third Party Advisory]
Changed Reference Type
http://www.securityfocus.com/bid/107906 No Types Assigned
http://www.securityfocus.com/bid/107906 Third Party Advisory, VDB Entry
Changed Reference Type
https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html No Types Assigned
https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html Third Party Advisory
Changed Reference Type
https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba@%3Cdev.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba@%3Cdev.tomcat.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/3d19773b4cf0377db62d1e9328bf9160bf1819f04f988315086931d7@%3Cdev.tomcat.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac@%3Ccommits.ofbiz.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/52ffb9fbf661245386a83a661183d13f1de2e5779fa23837a08e02ac@%3Ccommits.ofbiz.apache.org%3E Mailing List, Mitigation, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767@%3Cannounce.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/5f297a4b9080b5f65a05bc139596d0e437d6a539b25e31d29d028767@%3Cannounce.tomcat.apache.org%3E Mailing List, Mitigation, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a@%3Ccommits.ofbiz.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/673b6148d92cd7bc99ea2dcf85ad75d57da44fc322d51f37fb529a2a@%3Ccommits.ofbiz.apache.org%3E Mailing List, Mitigation, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3@%3Cnotifications.ofbiz.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/96849486813a95dfd542e1618b7923ca945508aaf4a4341f674d83e3@%3Cnotifications.ofbiz.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/a6c87a09a71162fd563ab1c4e70a08a103e0b7c199fc391f1c9c4c35@%3Ccommits.ofbiz.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/a6c87a09a71162fd563ab1c4e70a08a103e0b7c199fc391f1c9c4c35@%3Ccommits.ofbiz.apache.org%3E Mailing List, Mitigation, Vendor Advisory
Changed Reference Type
https://lists.apache.org/thread.html/dd4b325cdb261183dbf5ce913c102920a8f09c26dae666a98309165b@%3Cnotifications.ofbiz.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/dd4b325cdb261183dbf5ce913c102920a8f09c26dae666a98309165b@%3Cnotifications.ofbiz.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/ No Types Assigned
https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/ Third Party Advisory