OS Command Injection in Apache Tomcat - CVE-2019-0232
Published: April 11, 2019 / Updated: March 7, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to an input validation error within the CGI Servlet when passing arguments from JRE to the Windows environment. A remote attacker can send a specially crafted request to the CGI Servlet, inject and execute arbitrary OS commands on the system with Apache Tomcat privileges.
Successful exploitation of the vulnerability requires that Apache Tomcat is installed on Windows operating system with enabled option “enableCmdLineArguments” (CGI Servlet and “enableCmdLineArguments” option are disabled by default).
Affected software
Amazon Linux AMI
Oracle Retail Order Broker
Oracle Agile Engineering Data Management
Oracle Transportation Management
Oracle Database Server
MICROS Relate CRM Software
Instantis EnterpriseTrack
How to mitigate CVE-2019-0232
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote code execution in Apache Tomcat
- Amazon Linux AMI update for tomcat8
- Multiple vulnerabilities in Oracle Database Server
- OS Command Injection in Oracle Agile Engineering Data Management
- Multiple vulnerabilities in MICROS Relate CRM Software
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Multiple vulnerabilities in Oracle Retail Order Broker
- OS Command Injection in Oracle Transportation Management