Executive brief
Apache Tomcat's AJP Connector improperly manages privileges by treating AJP connections with higher trust than HTTP. An attacker can exploit this to read arbitrary files from the web application or process files as JSPs, potentially leading to remote code execution if file uploads are permitted.
Affected products
- Apache Tomcat 9.0.0.M1 to 9.0.0.30
- Apache Tomcat 8.5.0 to 8.5.50
- Apache Tomcat 7.0.0 to 7.0.99
Timeline
- 2020-02-24: patched: Apache Tomcat 9.0.31, 8.5.51, and 7.0.100 released with fixes.
- 2022-03-03: disclosed: NVD publication date.