Vulnerability record · CVE-2019-0193 · published 1 August 2019
CVE-2019-0193: Apache Solr DataImportHandler dataConfig parameter code injection
Apache · Solr
Apache Solr's DataImportHandler accepts a full DIH configuration through the request's dataConfig parameter, and because a DIH config can contain scripts, this parameter allows code injection. The debug mode of the DIH admin screen uses this parameter for convenience, making it a security risk. Solr 8.2.0 and later require the Java system property enable.dih.dataConfigParam to be set to true before the parameter can be used.
Description
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 HIGH, CISA KEV listed with a past due date, and EPSS above the 99th percentile indicate active exploitation, though the PR:H vector means an attacker first needs administrative access.
What it is
Apache Solr's DataImportHandler accepts a full DIH configuration through the request's dataConfig parameter, and because a DIH config can contain scripts, this parameter allows code injection. The debug mode of the DIH admin screen uses this parameter for convenience, making it a security risk. Solr 8.2.0 and later require the Java system property enable.dih.dataConfigParam to be set to true before the parameter can be used.
Impact
An attacker who can reach the DIH admin interface can inject and execute scripts through the dataConfig parameter, leading to code execution with the privileges of the Solr process. CVSS 3.1 scores this 7.2 HIGH with confidentiality, integrity and availability all rated high.
Attack surface
Reached over the network via the DIH admin screen's debug mode, which passes the dataConfig parameter. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so an attacker needs an administrative-level account on the Solr instance.
Exploitation
CVE-2019-0193 is listed in CISA KEV (added 2021-12-10, due 2022-06-10) and has an EPSS 30-day probability of 0.83547 (99.668th percentile), indicating active exploitation and very high likelihood. KEV notes no known ransomware campaign use.
What to do
- Upgrade Apache Solr to 8.2.0 or later, where the dataConfig parameter requires enable.dih.dataConfigParam=true.
- If upgrade is not possible, apply the vendor mitigation from SOLR-13669 and disable or restrict the DataImportHandler and its admin debug interface.
- Do not set enable.dih.dataConfigParam to true unless strictly required, and never expose the DIH admin screen to untrusted networks.
- Restrict network access to Solr admin endpoints to trusted management hosts only.
- Apply the Debian security updates referenced in the Debian LTS advisories for affected packages.
Detection
- Monitor Solr request logs for requests to DataImportHandler admin endpoints containing a dataConfig parameter.
- Alert on DIH debug-mode requests originating from outside expected administrative hosts or automation.
- Inspect Solr process behavior for unexpected child processes or script execution following DIH requests.
- Review Solr configuration for enable.dih.dataConfigParam being set to true and for exposed DIH admin handlers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0193 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Apache Solr DataImportHandler Code Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 10 June 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0193 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0193), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.