Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-17570

58
FAUCET Score

CVE-2019-17570 is a critical untrusted deserialization vulnerability in the unmaintained Apache XML-RPC library, affecting various distributions including Apache, Canonical, Debian, Fedora, and Red Hat. A malicious XML-RPC server can exploit this to execute arbitrary code on a vulnerable client, posing a severe risk with a CVSS score of 9.8. Despite its high severity and potential for complete compromise (C, I, A: H), there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
3.1CPE matchmatch criteria
cpe:2.3:a:apache:xml-rpc:3.1:*:*:*:*:*:*:*
3.1.1CPE matchmatch criteria
cpe:2.3:a:apache:xml-rpc:3.1.1:*:*:*:*:*:*:*
3.1.2CPE matchmatch criteria
cpe:2.3:a:apache:xml-rpc:3.1.2:*:*:*:*:*:*:*
3.1.3CPE matchmatch criteria
cpe:2.3:a:apache:xml-rpc:3.1.3:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
49.29%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.4929 is in the 96th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.6.0Fixed in: camel-xmlrpc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-java-common-xmlrpc-1:3.1.3-8.17.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-java-common-xmlrpc-1:3.1.3-8.17.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-java-common-xmlrpc-1:3.1.3-8.17.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: rh-java-common-xmlrpc-1:3.1.3-8.17.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSFixed in: rh-java-common-xmlrpc-1:3.1.3-8.17.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat JBoss Fuse 6Fixed in: camel-xmlrpc
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: xmlrpc
redhatend of lifevia redhat_api
Product: Red Hat Virtualization 4Fixed in: xmlrpc-common

Vendor Advisories (2)

mavenGHSA-6vwp-35w3-xph8critical

Insecure Deserialization in Apache XML-RPC

Jun 10, 2020
redhatCVE-2019-17570Important

xmlrpc: Deserialization of server-side exception from faultCause in XMLRPC error response

Jan 16, 2020

References

access.redhat.com / errata/RHSA-2020:0310
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
github.com / orangecertcc/security-research/security/advisories/GHSA-x2r6-4m45-m4jp
ExploitThird Party Advisory
lists.apache.org / thread.html/846551673bbb7ec8d691008215384bcef03a3fb004d2da845cfe88ee%401390230951%40%3Cdev.ws.apache.org%3E
Mailing ListVendor Advisory
lists.debian.org / debian-lts-announce/2020/01/msg00033.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/I3QCRLJYQRGVTIYF4BXYRFSF3ONP3TBF
seclists.org / bugtraq/2020/Feb/8
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202401-26
usn.ubuntu.com / 4496-1
PatchThird Party Advisory
debian.org / security/2020/dsa-4619
Third Party Advisory
openwall.com / lists/oss-security/2020/01/24/2
Mailing ListThird Party Advisory