AJP request injection vulnerability in Tomcat when using VirtualDirContext - CVE-2020-1938ID: oval:org.secpod.oval:def:61624 | Date: (C)2020-03-02 (M)2024-02-19 |
Class: VULNERABILITY | Family: unix |
The host is installed with Apache Tomcat 9.x before 9.0.31, 7.x before 7.0.100 or 8.5.x before 8.5.51 and is prone to an AJP request injection vulnerability. A flaw is present in application, which fails to properly handle a regression introduced due to refactoring. Successful exploitation allows remote attackers to execute code.
Platform: |
Debian 8.x |
Debian 9.x |
Debian 10.x |
Product: |
tomcat7 |
tomcat8 |
tomcat9 |
libservlet3.0-java |