CVE-2020-1938
published 2020-02-24CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-03-17
Exploited in the wild
EPSS
99.27%
99.9th percentile
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | apache_tomcat | — | — |
| apache | geode | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 7.0.0 < 7.0.100 | 7.0.100 |
| apache | tomcat | >= 8.5.0 < 8.5.51 | 8.5.51 |
| apache | tomcat | >= 9.0.0 < 9.0.31 | 9.0.31 |
| blackberry | good_control | <= 5.2.58.38 | — |
| blackberry | workspaces_server | — | — |
| blackberry | workspaces_server | — | — |
| blackberry | workspaces_server | — | — |
| blackberry | workspaces_server | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.31-1 (bookworm) | tomcat9 9.0.31-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| opensuse | leap | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for inbound connections to TCP port 8009 (AJP connector) from untrusted/external sources, which is the default attack vector for CVE-2020-1938. ↗
- →Check Point IPS signature 'Apache Tomcat AJP File Inclusion (CVE-2020-1938)' can be used for network-level detection. ↗
- →For RCE scenario, look for file uploads combined with AJP requests referencing uploaded files within the web application document root (e.g., webapps/APP/...). ↗
- →Detect vulnerable Tomcat instances by querying asset inventory for Tomcat versions 9.0.0–9.0.30, 8.5.0–8.5.50, 7.0.0–7.0.99, and any 6.x version. ↗
- →Malicious JSP code can be embedded within a variety of file types and uploaded, then triggered via the AJP connector to achieve RCE — inspect uploaded files for JSP content regardless of file extension. ↗
- ·The AJP connector is enabled by default in Tomcat 6, 7, 8, and 9; exploitation requires the AJP port (8009) to be reachable. RCE is only possible if the application also allows file uploads saved within the document root — it is NOT a default RCE vulnerability. ↗
- ·SysAid On-Premise 20.1.11 exposes the AJP port by default AND allows unauthenticated file uploads, making it a chained RCE scenario distinct from a standard Tomcat deployment. ↗
- ·Apache Tomcat 6.x is also affected but has no available patch; users must upgrade to a supported version. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_apache9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apache Tomcat Improper Privilege Management Vulnerability
cisa·2022-03-03·CVSS 9.8
CVE-2020-1938 [CRITICAL] Apache Tomcat Improper Privilege Management Vulnerability
Vulnerability: Apache Tomcat Improper Privilege Management Vulnerability
Affected: Apache Tomcat
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Remediation Due Date: 2022-03-17
Oracle
Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) — CVE-2020-1938
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-1938 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) — CVE-2020-1938
Oracle Oracle Supply Chain Risk Matrix: Folders, Files & Attachments (Apache Tomcat) vulnerability
CVE: CVE-2020-1938
CVSS: 9.8
Protocol: AJP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2020-1938
vendor_oracle·2020-07-15·CVSS 9.8
CVE-2020-1938 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2020-1938
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) vulnerability
CVE: CVE-2020-1938
CVSS: 9.8
Protocol: Apache JServ Protocol (AJP)
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
undertow: AJP File Read/Inclusion Vulnerability
vendor_redhat·2020-02-26·CVSS 8.6
CVE-2020-1745 [HIGH] CWE-285 undertow: AJP File Read/Inclusion Vulnerability
undertow: AJP File Read/Inclusion Vulnerability
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution.
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before. A remote, unauthenticated attacker could exploit this vu
Red Hat
tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
vendor_redhat·2020-02-20·CVSS 9.8
CVE-2020-1938 [CRITICAL] CWE-285 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - p
Debian
CVE-2020-1938: tomcat9 - When using the Apache JServ Protocol (AJP), care must be taken when trusting inc...
vendor_debian·2020·CVSS 9.8
CVE-2020-1938 [CRITICAL] CVE-2020-1938: tomcat9 - When using the Apache JServ Protocol (AJP), care must be taken when trusting inc...
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, i
Apache
Apache tomcat: CVE-2020-1938
vendor_apache·CVSS 9.8
CVE-2020-1938 [CRITICAL] Apache tomcat: CVE-2020-1938
Apache tomcat: CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. Prior to Tomcat 8.5.51, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. Prior to this vulnerability report, the known risks of an attacker being able to access the AJP port directly were: bypassing security checks based on client IP address bypassing user authentication if Tomcat was co
GHSA
Improper Privilege Management in Tomcat
ghsa·2020-06-15
CVE-2020-1938 [CRITICAL] CWE-269 Improper Privilege Management in Tomcat
Improper Privilege Management in Tomcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: returning arbitrary files from anywhere in the web application, processing any file in t
OSV
Improper Privilege Management in Tomcat
osv·2020-06-15
CVE-2020-1938 [CRITICAL] Improper Privilege Management in Tomcat
Improper Privilege Management in Tomcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: returning arbitrary files from anywhere in the web application, processing any file in t
OSV
CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat
osv·2020-02-24·CVSS 9.8
CVE-2020-1938 [CRITICAL] CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, i
VulnCheck
Apache Tomcat Improper Privilege Management Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-1938 [CRITICAL] Apache Tomcat Improper Privilege Management Vulnerability
Apache Tomcat Improper Privilege Management Vulnerability
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
Affected: Apache Tomcat
Required Action: Apply updates per vendor instructions.
Exploitation References: https://teamt5.org/tw/posts/technical-analysis-on-backdoor-bifrost-of-the-Chinese-apt-group-huapi/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.securin.io/wp-content/uploads/2023/08/2023-State-of-Cybersecurity-for-Medical-Devices-and-Healthcare-Systems.pdf; https://thedfirreport.com/2023/12/18/lets-opendir-some-presents-an-analysis-of-a-persistent-actors-activity/; https://a
Suricata
ET EXPLOIT Possible [401TRG] GhostCat LFI Successful Exploit (CVE-2020-1938)
suricata·2023-06-07·CVSS 9.8
CVE-2020-1938 [CRITICAL] ET EXPLOIT Possible [401TRG] GhostCat LFI Successful Exploit (CVE-2020-1938)
ET EXPLOIT Possible [401TRG] GhostCat LFI Successful Exploit (CVE-2020-1938)
Rule: alert http [$HOME_NET,$HTTP_SERVERS] 8009 -> any any (msg:"ET EXPLOIT Possible [401TRG] GhostCat LFI Successful Exploit (CVE-2020-1938)"; flow:established,to_client; flowbits:isset,ET.GhostCat; http.response_body; content:"|3c 3f|xml|20|version|3d 22|"; startswith; content:"Licensed|20|to|20|the|20|Apache|20|Software|20|Foundation|20 28|ASF|29 20|under|20|one|20|or|20|more|0a 20 20|contributor|20|license|20|agreements|2e|"; content:"The|20|ASF|20|licenses|20|this|20|file|20|to|20|You|20|under|20|the|20|Apache|20|License|2c 20|Version"; content:"aee/web-app_"; fast_pattern; content:"_"; distance:1; within:1; content:"|2e|xsd|22|"; content:"|3c|display|2d|name|3e|"; content:"|3c 2f|display|2d|name|3e|"; conte
Suricata
ET EXPLOIT [401TRG] GhostCat LFI Attempt Inbound (CVE-2020-1938)
suricata·2020-02-25·CVSS 9.8
CVE-2020-1938 [CRITICAL] ET EXPLOIT [401TRG] GhostCat LFI Attempt Inbound (CVE-2020-1938)
ET EXPLOIT [401TRG] GhostCat LFI Attempt Inbound (CVE-2020-1938)
Rule: alert tcp any any -> $HOME_NET 8009 (msg:"ET EXPLOIT [401TRG] GhostCat LFI Attempt Inbound (CVE-2020-1938)"; flow:established,to_server; flowbits:set,ET.GhostCat; content:"|12 34|"; depth:2; content:"|00 08|HTTP/1.1|00|"; distance:0; content:"javax.servlet.include.path_info|00|"; nocase; distance:0; content:"javax.servlet.include.request_uri|00|"; content:"javax.servlet.include.servlet_path|00|"; reference:cve,2020-1938; reference:url,www.tenable.com/blog/cve-2020-1938-ghostcat-apache-tomcat-ajp-file-readinclusion-vulnerability-cnvd-2020-10487; classtype:attempted-admin; sid:2029533; rev:4; metadata:affected_product Apache_Tomcat, attack_target Web_Server, created_at 2020_02_25, cve CVE_2020_1938, deployment Perimeter,
Exploit-DB
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
exploitdb·2020-11-13
CVE-2020-1938 Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
---
require "msf/core"
class MetasploitModule "Ghostcat",
"Description" => %q{
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechani
Exploit-DB
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
exploitdb·2020-02-20
CVE-2020-1938 Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
---
#!/usr/bin/env python
#CNVD-2020-10487 Tomcat-Ajp lfi
#by ydhcui
import struct
# Some references:
# https://tomcat.apache.org/connectors-doc/ajp/ajpv13a.html
def pack_string(s):
if s is None:
return struct.pack(">h", -1)
l = len(s)
return struct.pack(">H%dsb" % l, l, s.encode('utf8'), 0)
def unpack(stream, fmt):
size = struct.calcsize(fmt)
buf = stream.read(size)
return struct.unpack(fmt, buf)
def unpack_string(stream):
size, = unpack(stream, ">h")
if size == -1: # null string
return None
res, = unpack(stream, "%ds" % size)
stream.read(1) # \0
return res
class NotFoundException(Exception):
pass
class AjpBodyRequest(object):
# server == web server, container == servlet
SERVER_TO_CONTAINER, CONTAINER_TO_SERVER = range(2)
MAX_REQUEST_LE
Nuclei
Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability
nuclei·CVSS 9.8
CVE-2020-1938 [CRITICAL] Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability
Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed - returning arbitrary files from anywhere in the web application
Metasploit
Apache Tomcat AJP File Read
metasploit
Apache Tomcat AJP File Read
Apache Tomcat AJP File Read
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web ap
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
arxiv_fulltext·2023-06-07
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Soufian El Yadmani, Robin The, Olga Gadyatskaya
Leiden Institute of Advanced Computer Science, Leiden University
## Abstract
\
Exploit proof-of-concepts (PoCs) for known vulnerabilities are widely shared in the security community. They help security analysts to learn from each other and they facilitate security assessments and red teaming tasks. In the recent years, PoCs have been widely distributed, e.g., via dedicated websites and platforms, and public code repositories such as GitHub. However, there is no guarantee that PoCs in public code repositories come from trustworthy sources or even that they do what they are supposed to do.
In this work we investigate GitHub-hosted PoCs for known vulnerabili
arXiv
Towards Automated Attack Simulations of BPMN-based Processes
arxiv_fulltext·2021-06-16
Towards Automated Attack Simulations of BPMN-based Processes
Towards Automated Attack Simulations of BPMN-based Processes
Simon Hacks, Robert Lagerström
Division of Network and Systems Engineering
KTH Royal Institute of Technology
Stockholm, Sweden
\shacks|robertl\@kth.se
Daniel Ritter
SAP SE
Walldorf (Baden), Germany
[email protected]
## Abstract
Process digitization and integration is an increasing need for enterprises, while cyber-attacks denote a growing threat.
Using the Business Process Management Notation (BPMN) is common to handle the digital and integration focus within and across organizations.
In other parts of the same companies, threat modeling and attack graphs are used for analyzing the security posture and resilience.
In this paper, we propose a novel approach to use attack graph simulations on processes represented in
CTF
Easy / tomghost
ctf_writeups·CVSS 9.8
CVE-2020-1938 [CRITICAL] Easy / tomghost
# what I learn
- ghostcat
- gpg cracking
- gtfobin zip
# enumerating
- 22/tcp open ssh
- 53/tcp open domain
- 8009/tcp open ajp13
- 8080/tcp open http-proxy
- tomcat 9.0.30
# foothold
aftersome diging, tomcat version 9.0.30 is vulnerable to Ghostcat attack or CVE-2020-1938.
```
This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible
```
I found a exploit scrip call [ajpShooter
HackerOne
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
hackerone·2020-06-11·CVSS 4.3
[MEDIUM] Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
Tomcat examples available for public, Disclosure Apache Tomcat version, Critical/High/Medium CVE
**Summary:**
There are multiple issues found on ███:
1. ███████/examples/ - Apache Tomcat examples are available for public. Multiple issues - session and cookies manipulation, internals IP disclosure.
2. Error page contains information about Apache Tomcat version
3. Reported Tomcat version is vulnerable. Multiple CVEs - critical, high and medium
**Description:**
1. Examples are available by link: ███████/examples/
2. Information disclosure about Apache Tomcat version
3. Vulnerable version Apache Tomcat/8.5.33
https://nvd.nist.gov/vuln/detail/CVE-2020-1938
Base Score: 9.8 CRITICALVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2019-0232
Base Score
Bugzilla
CVE-2020-1745 undertow: AJP File Read/Inclusion Vulnerability
bugzilla·2020-02-26·CVSS 8.6
CVE-2020-1745 [HIGH] CVE-2020-1745 undertow: AJP File Read/Inclusion Vulnerability
CVE-2020-1745 undertow: AJP File Read/Inclusion Vulnerability
A file read/inclusion vulnerability was found in AJP connector in Undertow. This is enabled with a default AJP configuration port of 8009. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution (RCE).
Discussion:
External References:
https://www.cnvd.org.cn/webinfo/show/5415
https://www.tenable.com/blog/cve-2020-1938-ghostcat-apache-tomcat-ajp-file-readinclusion-vulnerability-cnvd-2020-10487
https://meterpreter.org/cve-2020-1938-apache-tomcat-a
Bugzilla
CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability [fedora-all]
bugzilla·2020-02-25·CVSS 9.8
CVE-2020-1938 [CRITICAL] CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability [fedora-all]
CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
bugzilla·2020-02-24·CVSS 9.8
CVE-2020-1938 [CRITICAL] CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
CVE-2020-1938 tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability
CVE-2020-1938 is a file read/inclusion vulnerability in the AJP connector in Apache Tomcat. This is enabled by default with a default configuration port of 8009. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution (RCE).
Discussion:
AJP is for mod_jk or mod_proxy_ajp and some other proxies, if you are not using an AJP proxy in front of your tomcat, you MUST have the AJP connector REMOVED from server.xml.
AJP is known as unencrypte
Dfir Report
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
blogs_dfir_report·2023-12-18
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Trendmicro
Operation Overtrap Targets Japanese Online Banking
blogs_trendmicro·2020-03-13
Operation Overtrap Targets Japanese Online Banking
Exploits & Vulnerabilities
# Operation Overtrap Targets Japanese Online Banking
Learn about the number of ways Operation Overtrap can infect or trap victims with its payload. Also, read about how to protect your personal identity data and money during tax-filing season.
By: Jon Clay
2020/03/13
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. This week, learn about the number of ways Operation Overtrap can infect or trap victims with its payload. Also, read about how to protect your personal identity data and money during tax-filing season.
Read on:
#### AWS Launches Bottlerocket, a Linux-based OS for Container Hosting
AWS has launched Bottlerocket, its
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Exploits y vulnerabilidades
## Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan Mar 10, 2020 Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability ( CVE-2020-1938 and CNVD-2020-10487 ) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most feared
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Exploits & Vulnerabilities
## Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan 2020/03/10 Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability ( CVE-2020-1938 and CNVD-2020-10487 ) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most feared Gh
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Sfruttamento vulnerabilità
## Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan Mar 10, 2020 Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability ( CVE-2020-1938 and CNVD-2020-10487 ) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most feared
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Ausnutzung von Schwachstellen
## Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan Mar 10, 2020 Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability ( CVE-2020-1938 and CNVD-2020-10487 ) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most fear
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Exploits & Vulnerabilities
## Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan Mar 10, 2020 Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability ( CVE-2020-1938 and CNVD-2020-10487 ) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most feared
Qualys
CVE-2020-1938 | Apache JServ (Protocol v1.3) AJP Vulnerability | Qualys
blogs_qualys·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] CVE-2020-1938 | Apache JServ (Protocol v1.3) AJP Vulnerability | Qualys
#### Table of Contents
- About CVE-2020-1938
- Exploitability
- IdentifyingCVE-2020-1938 Vulnerability using WAS scan
- Additional Attack Vector
- Remediation Guidance
- References
As previously reported, a severe vulnerability exists in Apache Tomcat’s Apache JServ Protocol. The Chinese cyber security company Chaitin Tech discovered the vulnerability, named “Ghostcat”, which is tracked using CVE-2020-1938 and rated critical severity with a CVSS v3 score of 9.8.
This blog post details how web application security teams can detect this vulnerability using Qualys Web Application Scanning (WAS). This new Qualys WAS detection complements the detection that uses Qualys VMDR®.
## About CVE-2020-1938
Apache Tomcat web servers are widely used for deploying Java-based web applications. Apache
Qualys
Detect Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys WAS
blogs_qualys·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Detect Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys WAS
## Table of Contents
About CVE-2020-1938
Exploitability
IdentifyingCVE-2020-1938 Vulnerability using WAS scan
Additional Attack Vector
Remediation Guidance
References
As previously reported , a severe vulnerability exists in Apache Tomcat’s Apache JServ Protocol. The Chinese cyber security company Chaitin Tech discovered the vulnerability , named “Ghostcat”, which is tracked using CVE-2020-1938 and rated critical severity with a CVSS v3 score of 9.8.
This blog post details how web application security teams can detect this vulnerability using Qualys Web Application Scanning (WAS) . This new Qualys WAS detection complements the detection that uses Qualys VMDR® .
## About CVE-2020-1938
Apache Tomcat web servers are widely used for deploying Java-based web applications. Apache JServ
Trendmicro
Busting Ghostcat: Analysis of CVE-2020-1938
blogs_trendmicro·2020-03-10·CVSS 9.8
CVE-2020-1938 [CRITICAL] Busting Ghostcat: Analysis of CVE-2020-1938
Exploits & Vulnerabilities
# Busting Ghostcat: Analysis of CVE-2020-1938
This analysis of the Apache Tomcat vulnerability seeks to put the most feared Ghostcat-related scenario into perspective by delving into the unlikely circumstances that would make it possible to allow an RCE through the vulnerability.
By: Magno Logan
2020/03/10
Read time: ( words)
Save to Folio
Discussions surrounding the Ghostcat vulnerability (CVE-2020-1938 and CNVD-2020-10487) found in Apache Tomcat puts it in the spotlight as researchers looked into its security impact, specifically its potential use for remote code execution (RCE).
Apache Tomcat is a popular open-source Java servlet container, so the discovery of Ghostcat understandably set off some alarms. This blog entry seeks to put the most feared Ghos
Qualys
Automatically Discover, Prioritize and Remediate Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys VMDR
blogs_qualys·2020-03-06·CVSS 9.8
CVE-2020-1938 [CRITICAL] Automatically Discover, Prioritize and Remediate Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys VMDR
A severe vulnerability exists in Apache Tomcat’s Apache JServ Protocol . The Chinese cyber security company Chaitin Tech discovered the vulnerability , which is named “Ghostcat” and is tracked using CVE-2020-1938 . The security issue has received a critical severity rating score of 9.8 based on CVSS v3 Scoring system.
Vulnerability Details:
Due to a file inclusion defect in the AJP service (port 8009) that is enabled by default in Tomcat, an attacker can construct a malicious request package for file inclusion operation, and then read the web directory file on the affected Tomcat server. If the system allows users to upload files, an attacker can upload malicious code to the server, and gain the ability to perform remote code execution.
Affected Versions:
Apache Tomcat 9.0.0 through 9.0.
Qualys
Automatically Discover, Prioritize and Remediate Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys VMDR | Qualys
blogs_qualys·2020-03-06·CVSS 9.8
CVE-2020-1938 [CRITICAL] Automatically Discover, Prioritize and Remediate Apache Tomcat AJP File Inclusion Vulnerability (CVE-2020-1938) using Qualys VMDR | Qualys
A severe vulnerability exists in Apache Tomcat’s Apache JServ Protocol. The Chinese cyber security company Chaitin Tech discovered the vulnerability, which is named “Ghostcat” and is tracked using CVE-2020-1938. The security issue has received a critical severity rating score of 9.8 based on CVSS v3 Scoring system.
Vulnerability Details:
Due to a file inclusion defect in the AJP service (port 8009) that is enabled by default in Tomcat, an attacker can construct a malicious request package for file inclusion operation, and then read the web directory file on the affected Tomcat server. If the system allows users to upload files, an attacker can upload malicious code to the server, and gain the ability to perform remote code execution.
Affected Versions:
Apache Tomcat 9.0.0 through 9.0.3
Checkpoint
24th February – Threat Intelligence Bulletin
blogs_checkpoint·2020-02-24
CVE-2020-3764 24th February – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th February – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 24th February 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point researchers are following an evolving, ongoing Malspam campaign that is targeting more than 80 Turkish companies with the Adwind remote access Trojan. “The Turkish Rat” uses different evasive methods to bypass security solutions.
Check Point SandBlast and Anti-Bot blades provide protection against th
Tenable
CVE-2020-1938: Ghostcat - Apache Tomcat AJP File Read/Inclusion Vulnerability (CNVD-2020-10487)
blogs_tenable·2020-02-21·CVSS 9.8
[CRITICAL] CVE-2020-1938: Ghostcat - Apache Tomcat AJP File Read/Inclusion Vulnerability (CNVD-2020-10487)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.htmlhttp://support.blackberry.com/kb/articleDetail?articleNumber=000062739https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200226-0002/https://www.debian.org/security/2020/dsa-4673https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.htmlhttp://support.blackberry.com/kb/articleDetail?articleNumber=000062739https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3Ehttps://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3Ehttps://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3Ehttps://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3Ehttps://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2020/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/https://security.gentoo.org/glsa/202003-43https://security.netapp.com/advisory/ntap-20200226-0002/https://www.debian.org/security/2020/dsa-4673https://www.debian.org/security/2020/dsa-4680https://www.oracle.com/security-alerts/cpujan2021.html
+ 3 more references
2020-02-24
Published
2022-03-03
Added to CISA KEV
Exploited in the wild