AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-12409

CRITICAL · CVSS 9.8 EPSS 22.26% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-11-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-12409
Severity
CRITICAL
CVSS
9.8
EPSS
22.26%
Apache

Original NVD Description

The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.