EXPOSURES › CVE-2020-1938
CVE-2020-1938
HIGH ⌖ ON CISA KEV · EXPLOITEDAn improperly managed privilege escalation in Apache Tomcat allowed attackers to bypass trust boundaries via AJP connections, leading to remote code execution.
Apache Tomcat treated Apache JServ Protocol (AJP) connections as inherently more trusted than HTTP connections, allowing attackers to exploit this privilege management flaw to execute arbitrary code remotely. This failure is critical for DIB organizations because it directly enables remote code execution (RCE), violates CMMC/NIST 800-171 requirements for patch management and access control, and can lead to full system compromise. Organizations must ensure Tomcat is patched to the latest version and restrict AJP connections to trusted internal networks only.
Shame score — A fundamental design flaw in privilege management that was actively exploited in the wild (KEV) to achieve remote code execution, demonstrating severe negligence in securing a widely deployed web server.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| BlackBerry Cloud - AtHoc Services for Government BlackBerry |
Authorized |
| BlackBerry CylanceProtect & CylanceOptics BlackBerry |
Authorized |
| BlackBerry Government Mobility Suite BlackBerry |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |