CVE-2020-1938

Apache Tomcat Improper Privilege Management Vulnerability

Description

Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.

Severity: CRITICAL

CVSS Score: 9.8

Vendor: Apache

Product: Tomcat

Loading CVE details...