CVE-2024-46544
published 2024-09-23CVE-2024-46544: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration…
PriorityP424medium5.9CVSS 3.1
AVLACLPRNUINSUCLILAL
EPSS
0.33%
24.8th percentile
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service.
This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected.
Users are recommended to upgrade to version 1.2.50, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat_connectors | >= 1.2.9 < 1.2.50 | 1.2.50 |
| apache_software_foundation | apache_tomcat_connectors | 1.2.9-beta – 1.2.49 | — |
| debian | debian_linux | — | — |
| debian | libapache-mod-jk | < libapache-mod-jk 1:1.2.48-2+deb12u2 (bookworm) | libapache-mod-jk 1:1.2.48-2+deb12u2 (bookworm) |
| ubuntu | libapache-mod-jk | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2582-53pq-96cq: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configur
ghsa_unreviewed·2024-09-23
CVE-2024-46544 [MEDIUM] CWE-276 GHSA-2582-53pq-96cq: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configur
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service.
This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected.
Users are recommended to upgrade to version 1.2.50, which fixes the issue.
OSV
CVE-2024-46544: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configur
osv·2024-09-23·CVSS 5.9
CVE-2024-46544 [MEDIUM] CVE-2024-46544: Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configur
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.
Ubuntu
Apache Tomcat Connectors vulnerability
vendor_ubuntu·2026-06-02
CVE-2024-46544 Apache Tomcat Connectors vulnerability
Title: Apache Tomcat Connectors vulnerability
Summary: Apache Tomcat Connectors could allow local users to expose sensitive
information or cause a denial of service.
It was discovered that Apache Tomcat Connectors used incorrect default
permissions for shared memory on Unix-like systems. A local attacker
could possibly use this issue to view or modify mod_jk configuration
data in shared memory, resulting in sensitive information exposure or a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
mod_jk: information Disclosure / DoS
vendor_redhat·2024-09-23·CVSS 5.9
CVE-2024-46544 [MEDIUM] CWE-276 mod_jk: information Disclosure / DoS
mod_jk: information Disclosure / DoS
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service.
This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected.
Users are recommended to upgrade to version 1.2.50, which fixes the issue.
An Incorrect Default Permissions vulnerability was found in Apache Tomcat Connectors that allows local users to view and modify shared memory containing mod_jk configuration, which may lead to information disclosure and denial of service.
Mitigation: Mitigation for this issu
Debian
CVE-2024-46544: libapache-mod-jk - Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows l...
vendor_debian·2024·CVSS 5.9
CVE-2024-46544 [MEDIUM] CVE-2024-46544: libapache-mod-jk - Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows l...
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected. Users are recommended to upgrade to version 1.2.50, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 1:1.2.48-2+deb12u2)
bullseye: resolved (fixed in 1:1.2.48-1+deb11u2)
forky: resolved (fixed in 1:1.2.50-1)
sid: resolved (fixed in 1:1.2.50-1)
trixie: resolved (fixed in 1:1.2.50-1)
No detection rules found.
No public exploits indexed.
2024-09-23
Published