EXPOSURES › CVE-2019-0193
CVE-2019-0193
HIGH ⌖ ON CISA KEV · EXPLOITEDApache Solr's DataImportHandler module suffered a code injection vulnerability that was actively exploited in the wild.
The DataImportHandler module in Apache Solr contained a code injection flaw allowing attackers to execute arbitrary code on vulnerable systems. This failure is critical for DIB organizations because it represents an unpatched, actively exploited vulnerability that could lead to system compromise, data exfiltration, or ransomware deployment. Organizations must ensure all optional Solr modules are patched and monitored for KEV-listed exploits.
Shame score — The vulnerability was actively exploited in the wild and listed in CISA's KEV catalog, indicating negligent patching and avoidable exposure to known threats.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The optional Apache Solr module DataImportHandler contains a code injection vulnerability.