FlawAtlas
Search the atlas
CVE-2019-0221 Moderate

Cross-site scripting in Apache Tomcat

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Exploit probability 45.6%
Published May 30, 2019
Required by Not available
Last source change June 18, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

27 explicit affected versions

Maven org.apache.tomcat.embed:tomcat-embed-core

109 explicit affected versions

Maven org.apache.tomcat:tomcat

85 explicit affected versions

Maven org.apache.tomcat:tomcat-catalina

109 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-0221

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

View original source
Open Source Vulnerabilities GHSA-jjpq-gp5q-8q6w

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

View original source

05 / REFERENCES

Further evidence