Junglewise Threat Intelligence

CVE-2020-1938: Improper Privilege Management in Tomcat

CVE-2020-1938 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2020-06-15

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat's AJP Connector improperly manages privileges by treating AJP connections with higher trust than HTTP. An attacker can exploit this to read arbitrary files from the web application or process files as JSPs, potentially leading to remote code execution if file uploads are permitted.

Affected products

  • Apache Tomcat 9.0.0.M1 to 9.0.0.30
  • Apache Tomcat 8.5.0 to 8.5.50
  • Apache Tomcat 7.0.0 to 7.0.99

Timeline

  • 2020-02-24: patched: Apache Tomcat 9.0.31, 8.5.51, and 7.0.100 released with fixes.
  • 2022-03-03: disclosed: NVD publication date.

Related threats