logo

Apache TomCat AJP File Inclusion Vulnerability

ID: 443b0af5-d56c-5e7e-a8fd-fe2663f45203

STIX ID: report--443b0af5-d56c-5e7e-a8fd-fe2663f45203

Feed Name: FortiGuard Threat Signals

Threat Score
80/100

Date Published: 2025-07-24

Date Updated: 2026-07-28

...
...

FortiGuard Labs reports on "GhostCat" (CVE-2020-1938), a critical Apache Tomcat AJP file-inclusion vulnerability that can allow attackers to read/write webapp directories and potentially achieve remote code execution by uploading malicious JSPs; it affects Tomcat 7.0.x through 9.0.30, has a CVSS base score of 9.8, patches are available for supported releases, and mitigations include disabling the AJP connector or restricting its network exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.