Vulnerability record · CVE-2019-0192 · published 7 March 2019
CVE-2019-0192: Apache Solr Config API JMX RMI deserialization RCE
Apache · Solr
Apache Solr 5.0.0-5.5.5 and 6.0.0-6.6.5 let the Config API set the JMX server through an HTTP POST. Pointing that setting at a malicious RMI server abuses Solr's unsafe deserialization to run code on the Solr host. It matters because the endpoint is network-reachable with no credentials and the result is full remote code execution.
Description
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP POST request. By pointing it to a malicious RMI server, an attacker could take advantage of Solr's unsafe deserialization to trigger remote code execution on the Solr side.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with CVSS 9.8 and very high EPSS, though not in KEV.
What it is
Apache Solr 5.0.0-5.5.5 and 6.0.0-6.6.5 let the Config API set the JMX server through an HTTP POST. Pointing that setting at a malicious RMI server abuses Solr's unsafe deserialization to run code on the Solr host. It matters because the endpoint is network-reachable with no credentials and the result is full remote code execution.
Impact
An unauthenticated attacker gains remote code execution on the Solr server, giving full control of the process and its data. CVSS 3.0 scores it 9.8 with high confidentiality, integrity and availability impact.
Attack surface
Reached over the network via an HTTP POST to the Solr Config API that sets the JMX/RMI target; the CVSS vector shows no privileges and no user interaction required. Any Solr instance exposing the Config API is a candidate.
Exploitation
Not listed in CISA KEV and no ransomware groups are documented for it, but EPSS is 0.775 (99.5th percentile), indicating high predicted exploitation activity. References are vendor advisories and mailing-list mitigation notes, not public exploit code.
What to do
- Upgrade Solr to a fixed release outside the affected 5.0.0-5.5.5 and 6.0.0-6.6.5 ranges; patch first.
- Restrict network access to the Solr Config API and admin endpoints to trusted hosts only.
- Disable or lock down JMX/RMI configuration where it is not required.
- Apply the vendor mitigation guidance referenced in the Apache announcement.
- Monitor and alert on Config API POST requests that set JMX or RMI targets.
Detection
- Alert on HTTP POST requests to Solr Config API paths that modify JMX or RMI settings.
- Monitor Solr process outbound connections to unexpected RMI endpoints.
- Watch for deserialization or class-loading errors and unusual child processes spawned by Solr.
- Audit Solr admin/Config API access logs for requests from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0192 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0192), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.