Apache Tomcat AJP Connector Arbitrary File Read

Strike ID:
E20-0zwy1
CVSS:
8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
False Positive:
f
Variants:
12
Year:
2020

Description

An arbitrary file read (which can be turned into local file inclusion under special circumstances) exists in Apache Tomcat's AJP Connector, versions before 9.0.31, 8.5.51, and 7.0.100. Dubbed as 'Ghostcat', the flaw exists due to lack of authentication when requesting resources via AJP binary protocol on port 8009. Unauthenticated remote attackers may be able to read arbitrary files residing within server's root path.

CVE

References