← All CVEs

CVE-2019-10097

high · 7.2

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by untrusted HTTP clients.

7.2
CVSS
52.9%
EPSS (exploit prob.)
99th
EPSS percentile
2019-09-26
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-476CWE-787

Affected products

VendorProductAffected versions
apachehttp_server2.4.33
apachehttp_server2.4.34
apachehttp_server2.4.35
apachehttp_server2.4.37
apachehttp_server2.4.38
oraclecommunications_element_manager8.0.0
oraclecommunications_element_manager8.1.0
oraclecommunications_element_manager8.1.1
oraclecommunications_element_manager8.2.0
oraclecommunications_session_report_manager8.1.1
oraclecommunications_session_report_manager8.2.0
oraclecommunications_session_report_manager8.2.1
oraclecommunications_session_route_manager8.1.1
oraclecommunications_session_route_manager8.2.0
oraclecommunications_session_route_manager8.2.1
oracleenterprise_manager_ops_center12.3.3
oracleenterprise_manager_ops_center12.4.0
oraclehttp_server12.2.1.4.0
oracleinstantis_enterprisetrack>= 17.1, <= 17.3
oracleretail_xstore_point_of_service7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-10097