Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 65.0%; technical severity is CVSS 7.8.
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Who should care
- Teams operating HTTP Server, Ubuntu Linux, Debian Linux +24 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether HTTP Server, Ubuntu Linux, Debian Linux +24 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch Cpuapr2020
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Oracle Security patch Cpuapr2020Oracle · Vendor sourceVerification pending ↗
- Oracle Security patch Cpujul2019 5072835Oracle · Vendor sourceVerification pending ↗
- Oracle Security patch Cpuoct2019 5072832Oracle · Vendor sourceVerification pending ↗
- Lists Apache Security patchLists ApacheVerification pending ↗
- Seclists Security patchSeclistsVerification pending ↗
Upgrade
- Lists Opensuse Security release notes Msg00051Lists OpensuseVerification pending ↗
- Lists Opensuse Security release notes Msg00061Lists OpensuseVerification pending ↗
- Lists Fedoraproject Security release notes ALIR5S3O7NRHEGFMIDMUSYQIZOE4TJJNLists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7Lists FedoraprojectVerification pending ↗
- Lists Fedoraproject Security release notes WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGTLists FedoraprojectVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-416
- Affected versions
- Apache HTTP Server (Start Including 2.4.17, End Including 2.4.38); Canonical Ubuntu Linux (Version 14.04 | Version 16.04 | Version 18.04 | Version 18.10); Debian Debian Linux (Version 9.0); Fedoraproject Fedora (Version 28 | Version 29 | Version 30); Netapp Oncommand Unified Manager (Version -); Opensuse Leap (Version 15.0 | Version 42.3); Oracle Communications Session Report Manager (Version 8.0.0 | Version 8.1.0 | Version 8.1.1 | Version 8.2.0); Oracle Communications Session Route Manager (Version 8.0.0 | Version 8.1.0 | Version 8.1.1 | Version 8.2.0)
- Fixed versions
- No explicit fixed version is currently recorded.
- Published
- 8 April 2019
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 65.0%
- Signal calculated at 79
External references
- Red Hat Third-party advisory RHBA 2019:0959
- Red Hat Third-party advisory RHSA-2019:0746
- Red Hat Third-party advisory RHSA-2019:0980
- Red Hat Third-party advisory RHSA-2019:1296
- Red Hat Third-party advisory RHSA-2019:1297
- Red Hat Third-party advisory RHSA-2019:1543
- F5 Third-party advisory K32957101
- HPE Third-party advisory Display
- Ubuntu Third-party advisory 3937 1
- CISA Government advisory CVE-2019-0211
- Lists Opensuse Third-party advisory Msg00084
- Packetstormsecurity Third-party advisory Apache 2.4.38 Root Privilege Escalation