← Back

CVE-2019-0211

nvd nist
Published: Apr 8, 2019Modified: Oct 27, 2025CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Affected (68)

Show all products
1 product
Http Server
1 product
Fedora
1 product
Ubuntu Linux
1 product
Debian Linux
1 product
Leap
1 product
Oncommand Unified Manager
15 products
Enterprise Linux
Enterprise Linux Eus
Enterprise Linux For Arm 64
Enterprise Linux For Arm 64 Eus
Enterprise Linux Server Aus
Enterprise Linux Server Tus
Jboss Core Services
Openshift Container Platform
Software Collections
6 products
Enterprise Manager Ops Center
Http Server
Instantis Enterprisetrack
Retail Xstore Point Of Service
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.4.17 to 2.4.38
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 28
Version 29
Version 30
Configuration C
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 18.10
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 42.3
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration G
40 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 8.0_aarch64
Redhat
Version 8.1_aarch64
Version 8.2_aarch64
Version 8.4_aarch64
Version 8.6_aarch64
Version 8.8_aarch64
Version 8.0_s390x
Redhat
Version 8.1_s390x
Version 8.2_s390x
Version 8.4_s390x
Version 8.6_s390x
Version 8.8_s390x
Version 8.0_ppc64le
Redhat
Version 8.1_ppc64le
Version 8.2_ppc64le
Version 8.4_ppc64le
Version 8.6_ppc64le
Version 8.8_ppc64le
Redhat
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 8.0
Version 8.1
Version 8.4
Version 8.6
Version 8.8
Version 1.0
Version 3.11
Version 3.11_ppc64le
Version 1.0
Configuration H
16 vulnerable

References (103)

Source: security@apache.org
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: security@apache.org
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: security@apache.org
Broken LinkThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
Broken LinkVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing List
Source: security@apache.org
Broken LinkThird Party AdvisoryVDB Entry
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Vendor Advisory
Source: security@apache.org
Mailing ListPatchThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
ExploitThird Party AdvisoryVDB Entry
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkMailing ListRelease NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.