Apache TomCat AJP File Inclusion Vulnerability
ID: 443b0af5-d56c-5e7e-a8fd-fe2663f45203
STIX ID: report--443b0af5-d56c-5e7e-a8fd-fe2663f45203
Feed Name: FortiGuard Threat Signals
Threat Score
FortiGuard Labs reports on "GhostCat" (CVE-2020-1938), a critical Apache Tomcat AJP file-inclusion vulnerability that can allow attackers to read/write webapp directories and potentially achieve remote code execution by uploading malicious JSPs; it affects Tomcat 7.0.x through 9.0.30, has a CVSS base score of 9.8, patches are available for supported releases, and mitigations include disabling the AJP connector or restricting its network exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
