PT-2020-1704 · Apache+5 · Apache Tomcat+5

CVE-2020-1938

·

Published

2020-02-11

·

Updated

2026-09-07

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.0.30 Apache Tomcat versions 8.5.0 through 8.5.50 Apache Tomcat versions 7.0.0 through 7.0.99
Description Apache Tomcat treats connections using the Apache JServ Protocol (AJP) with a higher level of trust than HTTP connections. The AJP Connector was enabled by default and listened on all configured IP addresses, which can be exploited if the AJP port is accessible to untrusted users. This issue allows an attacker to return arbitrary files from anywhere within the web application, including the WEB-INF and META-INF directories, or any location reachable via ServletContext.getResourceAsStream(). Additionally, it allows processing any file within the web application as a JSP. If the application permits file uploads or if an attacker can otherwise control the application content, this capability can lead to remote code execution. Other risks include bypassing security checks based on client IP addresses and bypassing user authentication if Tomcat is configured to trust authentication data from a reverse proxy.
Recommendations Update Apache Tomcat versions 9.0.0.M1 through 9.0.0.30 to version 9.0.31 or later. Update Apache Tomcat versions 8.5.0 through 8.5.50 to version 8.5.51 or later. Update Apache Tomcat versions 7.0.0 through 7.0.99 to version 7.0.100 or later. Disable the AJP Connector if it is not required. Restrict access to the AJP port to prevent untrusted users from connecting.

Exploit

Fix

Improper Authorization

RCE

Improper Privilege Management

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AJPCVE2020_1938
ALSA-2020_4751
ALSA-2025_1210
ALSA-2025_1215
ALSA-2025_1300
ALSA-2025_1301
ALSA-2025_1306
ALSA-2025_1309
ALSA-2025_1314
ALSA-2025_1329
ALSA-2025_1338
ALSA-2025_1346
ALSA-2025_16880
ALT-PU-2020-2892
ALT-PU-2020-3213
ALT-PU-2021-2858
BDU:2020-00937
BDU:2020-02853
BIT-TOMCAT-2020-1938
CESA-2020_0855
CESA-2020_0912
CESA-2020_4847
CVE-2020-1938
DLA-2133-1
DLA-2209-1
DSA-4673-1
DSA-4680-1
ELSA-2020-0855
ELSA-2020-0912
GHSA-C9HW-WF7X-JP9J
GHSA-GV2W-88HX-8M9R
MGASA-2020-0138
OPENSUSE-SU-2020:0345-1
OPENSUSE-SU-2020:0597-1
OPENSUSE-SU-2020_0345-1
OPENSUSE-SU-2020_0597-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2020:0813
RHSA-2020:0855
RHSA-2020:0861
RHSA-2020:0912
RHSA-2020:0962
RHSA-2020:1478
RHSA-2020:1520
RHSA-2020:2058
RHSA-2020:2059
RHSA-2020:2060
RHSA-2020:2511
RHSA-2020:2512
RHSA-2020:2513
RHSA-2020:2779
RHSA-2020:2780
RHSA-2020:2781
RHSA-2020:2840
RHSA-2020:4847
RHSA-2020_0855
RHSA-2020_0912
RHSA-2020_4847
RHSA-2024:5856
RLSA-2020:4847
RLSA-2020_4847
SUSE-SU-2020:0598-1
SUSE-SU-2020:0631-1
SUSE-SU-2020:0632-1
SUSE-SU-2020:0725-1
SUSE-SU-2020:0806-1
SUSE-SU-2020:1111-1
SUSE-SU-2020:1126-1
SUSE-SU-2020:1272-1
SUSE-SU-2020:14334-1
SUSE-SU-2020:14342-1
SUSE-SU-2020_0598-1
SUSE-SU-2020_0631-1
SUSE-SU-2020_0632-1
SUSE-SU-2020_0725-1
SUSE-SU-2020_0806-1
SUSE-SU-2020_1111-1
SUSE-SU-2020_1126-1
SUSE-SU-2020_1272-1
SUSE-SU-2020_14334-1
SUSE-SU-2020_14342-1

Affected Products

Alt Linux
Apache Tomcat
Centos
Red Hat
Rocky Linux
Suse