Unknown
CVE-2019-10097
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-10097
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the “PROXY” protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- apache,
- oracle
Products
- communications element manager 8.0.0,
- communications element manager 8.1.0,
- communications element manager 8.1.1,
- communications element manager 8.2.0,
- communications session report manager 8.1.1,
- communications session report manager 8.2.0,
- communications session report manager 8.2.1,
- communications session route manager 8.1.1,
- communications session route manager 8.2.0,
- communications session route manager 8.2.1,
- enterprise manager ops center 12.3.3,
- enterprise manager ops center 12.4.0,
- http server 12.2.1.4.0,
- http server 2.4.33,
- http server 2.4.34,
- http server 2.4.35,
- http server 2.4.37,
- http server 2.4.38,
- instantis enterprisetrack,
- retail xstore point of service 7.1
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: