Skip to content
COOEY

EXPOSURES › CVE-2020-1938

CVE-2020-1938

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-1938 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrceprivilege-escalation

An improperly managed privilege escalation in Apache Tomcat allowed attackers to bypass trust boundaries via AJP connections, leading to remote code execution.

Apache Tomcat treated Apache JServ Protocol (AJP) connections as inherently more trusted than HTTP connections, allowing attackers to exploit this privilege management flaw to execute arbitrary code remotely. This failure is critical for DIB organizations because it directly enables remote code execution (RCE), violates CMMC/NIST 800-171 requirements for patch management and access control, and can lead to full system compromise. Organizations must ensure Tomcat is patched to the latest version and restrict AJP connections to trusted internal networks only.

Shame score — A fundamental design flaw in privilege management that was actively exploited in the wild (KEV) to achieve remote code execution, demonstrating severe negligence in securing a widely deployed web server.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

AFFECTED FEDRAMP PRODUCTS · 14
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
BlackBerry Cloud - AtHoc Services for Government
BlackBerry
Authorized
BlackBerry CylanceProtect & CylanceOptics
BlackBerry
Authorized
BlackBerry Government Mobility Suite
BlackBerry
Authorized
Cloud Insights
NetApp
In Process
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized