CVE-2020-1938
Apache Tomcat’s default AJP connector can be exploited by attackers to read arbitrary files and execute code. The vulnerability allows remote code execution if the connector is reachable from untrusted networks. It is critical because it can compromise any Tomcat instance exposed to the internet.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Tomcat versions 7.0.0–7.0.99, 8.5.0–8.5.50, and 9.0.0.M1–9.0.0.30 that ship with the AJP connector enabled by default. Other products that embed Tomcat or the AJP connector, such as Apache Geode 1.12.0 and various Oracle Agile and communications products, are also affected.
Real-world impact
An attacker who can reach the AJP port can read any file on the server, upload malicious files, and have them executed as JSP, giving full control over the application and potentially the underlying operating system.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is remotely exploitable with no authentication, provides complete compromise of confidentiality, integrity, and availability, and can be triggered from any network location.
What to do about it
- 01Upgrade Tomcat to version 9.0.31 or later, 8.5.51 or later, or 7.0.100 or later.
- 02If an upgrade is not possible, disable the AJP connector or restrict it to trusted IP addresses.
- 03Restart Tomcat to apply the changes.
CISA KEV required action and NVD vendor advisory
Timeline
- Feb 24, 2020 · Feb 24, 2020PublishedDisclosed and added to the National Vulnerability Database.
- Mar 3, 2022 · Mar 3, 2022Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Mar 17, 2022 · Mar 17, 2022CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 25, 2026 · 19d agoAdvisory updatedThe NVD record was last revised.
- Aug 25, 2026 · 19d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- lists.opensuse.org/opensuse-security-announce/…third party advisory
- lists.opensuse.org/opensuse-security-announce/…mailing listthird party advisory
- support.blackberry.com/kb/articleDetailthird party advisory
- lists.apache.org/thread.html/r089dc67c0358a1…mailing list
- lists.apache.org/thread.html/r1125f3044a0946…mailing list
- lists.apache.org/thread.html/r17aaa3a05b5b7f…mailing list
- lists.apache.org/thread.html/r38a5b7943b9a62…mailing list
- lists.apache.org/thread.html/r43faacf64570b1…mailing list
- lists.apache.org/thread.html/r47caef01f66310…mailing list
- lists.apache.org/thread.html/r4afa11e0464408…issue trackingmailing list
- lists.apache.org/thread.html/r4f86cb260196e5…mailing list
- lists.apache.org/thread.html/r549b43509e387a…mailing list
- lists.apache.org/thread.html/r57f5e4ced436ac…mailing list
- lists.apache.org/thread.html/r5e2f1201b92ee0…mailing list
- lists.apache.org/thread.html/r61f280a76902b5…mailing list
- lists.apache.org/thread.html/r6a5633cad1b560…mailing list
- lists.apache.org/thread.html/r74328b178f9f37…mailing list
- lists.apache.org/thread.html/r75113652e46c4d…mailing list
- lists.apache.org/thread.html/r772335e6851ad3…issue trackingmailing list
- lists.apache.org/thread.html/r7c6f492fbd39af…mailing listvendor advisory