AJP request injection vulnerability in Apache Tomcat - CVE-2020-1938 (rpm)Deprecated |
ID: oval:org.secpod.oval:def:61640 | Date: (C)2020-03-02 (M)2024-02-19 |
Class: VULNERABILITY | Family: unix |
The host is installed with Apache Tomcat 9.x before 9.0.31, 7.x before 7.0.100 or 8.5.x before 8.5.51 and is prone to an AJP request injection vulnerability. A flaw is present in application, which fails to properly handle a regression introduced due to refactoring. Successful exploitation allows remote attackers to execute code.
Platform: |
CentOS 6 |
CentOS 7 |
Red Hat Enterprise Linux 6 |
Red Hat Enterprise Linux 7 |
Product: |
tomcat |
tomcat-servlet |