First published: Tue Dec 31 2019(Updated: )
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios | =5.6.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20197 has a high severity due to its ability to allow authenticated users to execute arbitrary OS commands.
To fix CVE-2019-20197, upgrade Nagios XI to a patched version that addresses this vulnerability.
Nagios XI version 5.6.9 is affected by CVE-2019-20197.
CVE-2019-20197 is a remote code execution vulnerability that can be exploited in a web application context.
CVE-2019-20197 occurs when shell metacharacters are improperly handled in the id parameter of schedulereport.php.