{"cve":{"cve_id":"CVE-2020-1938","is_kev":true,"kev_date_added":"2022-03-03","kev_vendor_project":"Apache","kev_product":"Tomcat","kev_vulnerability_name":"Apache Tomcat Improper Privilege Management Vulnerability","kev_short_description":"Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.","kev_required_action":"Apply updates per vendor instructions.","kev_due_date":"2022-03-17","kev_known_ransomware":false,"kev_notes":"https://nvd.nist.gov/vuln/detail/CVE-2020-1938","kev_cwes":[],"epss_score":0.9927,"epss_percentile":0.99934,"epss_as_of":"2026-08-26","description":"When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.","published_at":"2020-02-24T21:19:18Z","last_modified_at":"2026-08-25T16:28:27.310000Z","cvss_v3_score":9.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":null,"nvd_references":["https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","https://security.gentoo.org/glsa/202003-43","https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/","https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","https://www.debian.org/security/2020/dsa-4673","https://www.debian.org/security/2020/dsa-4680","https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://security.netapp.com/advisory/ntap-20200226-0002/","http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E"],"vuln_status":"Analyzed","trending_score":0.6186860000000001,"is_trending":true,"has_trended":true,"trended_number_one":false,"trending_peak_score":0.6186860000000001,"trending_peak_rank":2,"started_trending_at":"2026-08-26T01:37:50.373238Z","trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-08-27T17:44:58.711341Z"},"effective_severity":"CRITICAL","badges":["kev","exploit","trending","epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"apache","vendor_name":"apache","product_slug":"apache-tomcat","product_name":"Apache Tomcat","version_start":"8.5.0 to 8.5.50","version_start_inclusive":true,"version_end":"8.5.0 to 8.5.50","version_end_inclusive":true,"cpe23_uri":"cve5:apache:apache-tomcat:8.5.0 to 8.5.50:8.5.0 to 8.5.50"},{"vendor_slug":"apache","vendor_name":"apache","product_slug":"apache-tomcat","product_name":"Apache Tomcat","version_start":"7.0.0 to 7.0.99","version_start_inclusive":true,"version_end":"7.0.0 to 7.0.99","version_end_inclusive":true,"cpe23_uri":"cve5:apache:apache-tomcat:7.0.0 to 7.0.99:7.0.0 to 7.0.99"},{"vendor_slug":"apache","vendor_name":"apache","product_slug":"apache-tomcat","product_name":"Apache Tomcat","version_start":"Apache Tomcat 9.0.0.M1 to 9.0.0.30","version_start_inclusive":true,"version_end":"Apache Tomcat 9.0.0.M1 to 9.0.0.30","version_end_inclusive":true,"cpe23_uri":"cve5:apache:apache-tomcat:Apache Tomcat 9.0.0.M1 to 9.0.0.30:Apache Tomcat 9.0.0.M1 to 9.0.0.30"},{"vendor_slug":"apache","vendor_name":"apache","product_slug":"geode","product_name":"geode","version_start":"1.12.0","version_start_inclusive":true,"version_end":"1.12.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:apache:geode:1.12.0:*:*:*:*:*:*:*"},{"vendor_slug":"apache","vendor_name":"apache","product_slug":"tomcat","product_name":"Tomcat","version_start":"7.0.0","version_start_inclusive":true,"version_end":"7.0.100","version_end_inclusive":false,"cpe23_uri":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"},{"vendor_slug":"blackberry","vendor_name":"BlackBerry","product_slug":"good-control","product_name":"good_control","version_start":null,"version_start_inclusive":null,"version_end":"5.2.58.38","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:blackberry:good_control:*:*:*:*:*:*:*:*"},{"vendor_slug":"blackberry","vendor_name":"BlackBerry","product_slug":"workspaces-server","product_name":"Workspaces Server","version_start":"8.1.0","version_start_inclusive":true,"version_end":"8.1.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:blackberry:workspaces_server:8.1.0:*:*:*:*:*:*:*"},{"vendor_slug":"blackberry","vendor_name":"BlackBerry","product_slug":"workspaces-server","product_name":"Workspaces Server","version_start":"7.0.1","version_start_inclusive":true,"version_end":"7.0.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:blackberry:workspaces_server:7.0.1:*:*:*:*:*:*:*"},{"vendor_slug":"blackberry","vendor_name":"BlackBerry","product_slug":"workspaces-server","product_name":"Workspaces Server","version_start":"7.1.2","version_start_inclusive":true,"version_end":"7.1.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:blackberry:workspaces_server:7.1.2:*:*:*:*:*:*:*"},{"vendor_slug":"blackberry","vendor_name":"BlackBerry","product_slug":"workspaces-server","product_name":"Workspaces Server","version_start":"9.0","version_start_inclusive":true,"version_end":"9.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:blackberry:workspaces_server:9.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"9.0","version_start_inclusive":true,"version_end":"9.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"10.0","version_start_inclusive":true,"version_end":"10.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"8.0","version_start_inclusive":true,"version_end":"8.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"31","version_start_inclusive":true,"version_end":"31","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"30","version_start_inclusive":true,"version_end":"30","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"32","version_start_inclusive":true,"version_end":"32","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"},{"vendor_slug":"netapp","vendor_name":"NETAPP","product_slug":"data-availability-services","product_name":"data_availability_services","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*"},{"vendor_slug":"netapp","vendor_name":"NETAPP","product_slug":"oncommand-system-manager","product_name":"oncommand_system_manager","version_start":"3.0.0","version_start_inclusive":true,"version_end":"3.1.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*"},{"vendor_slug":"opensuse","vendor_name":"openSUSE","product_slug":"leap","product_name":"Leap","version_start":"15.1","version_start_inclusive":true,"version_end":"15.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"agile-engineering-data-management","product_name":"agile_engineering_data_management","version_start":"6.2.1.0","version_start_inclusive":true,"version_end":"6.2.1.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"agile-product-lifecycle-management","product_name":"agile_product_lifecycle_management","version_start":"9.3.5","version_start_inclusive":true,"version_end":"9.3.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"agile-product-lifecycle-management","product_name":"agile_product_lifecycle_management","version_start":"9.3.6","version_start_inclusive":true,"version_end":"9.3.6","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"agile-product-lifecycle-management","product_name":"agile_product_lifecycle_management","version_start":"9.3.3","version_start_inclusive":true,"version_end":"9.3.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"communications-element-manager","product_name":"communications_element_manager","version_start":"8.1.1","version_start_inclusive":true,"version_end":"8.1.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"communications-element-manager","product_name":"communications_element_manager","version_start":"8.2.0","version_start_inclusive":true,"version_end":"8.2.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"communications-element-manager","product_name":"communications_element_manager","version_start":"8.2.1","version_start_inclusive":true,"version_end":"8.2.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"communications-instant-messaging-server","product_name":"communications_instant_messaging_server","version_start":"10.0.1.4.0","version_start_inclusive":true,"version_end":"10.0.1.4.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"health-sciences-empirica-inspections","product_name":"health_sciences_empirica_inspections","version_start":"1.0.1.2","version_start_inclusive":true,"version_end":"1.0.1.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"health-sciences-empirica-signal","product_name":"health_sciences_empirica_signal","version_start":"7.3.3","version_start_inclusive":true,"version_end":"7.3.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"hospitality-guest-access","product_name":"hospitality_guest_access","version_start":"4.2.0","version_start_inclusive":true,"version_end":"4.2.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"hospitality-guest-access","product_name":"hospitality_guest_access","version_start":"4.2.1","version_start_inclusive":true,"version_end":"4.2.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"instantis-enterprisetrack","product_name":"instantis_enterprisetrack","version_start":"17.1","version_start_inclusive":true,"version_end":"17.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"mysql-enterprise-monitor","product_name":"MySQL Enterprise Monitor","version_start":null,"version_start_inclusive":null,"version_end":"4.0.12","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"siebel-ui-framework","product_name":"Siebel UI Framework","version_start":null,"version_start_inclusive":null,"version_end":"20.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"transportation-management","product_name":"transportation_management","version_start":"6.3.7","version_start_inclusive":true,"version_end":"6.3.7","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"workload-manager","product_name":"workload_manager","version_start":"18c","version_start_inclusive":true,"version_end":"18c","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"workload-manager","product_name":"workload_manager","version_start":"12.2.0.1","version_start_inclusive":true,"version_end":"12.2.0.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*"},{"vendor_slug":"oracle","vendor_name":"oracle","product_slug":"workload-manager","product_name":"workload_manager","version_start":"19c","version_start_inclusive":true,"version_end":"19c","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*"}],"exploit_refs":[{"source":"exploit-db","kind":"exploit-db","url":"https://www.exploit-db.com/exploits/49039","title":"Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)","author":"SunCSR","disclosed_at":"2020-11-13"},{"source":"exploit-db","kind":"exploit-db","url":"https://www.exploit-db.com/exploits/48143","title":"Apache Tomcat - AJP 'Ghostcat File Read/Inclusion","author":"YDHCUI","disclosed_at":"2020-02-20"},{"source":"nuclei","kind":"nuclei","url":"https://github.com/projectdiscovery/nuclei-templates/blob/main/network/cves/2020/CVE-2020-1938.yaml","title":"Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability","author":"milo2012","disclosed_at":null}],"news":[],"references":[{"url":"https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r856cdd87eda7af40b50278d6de80ee4b42d63adeb433a34a7bdaf9db%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r75113652e46c4dee687236510649acfb70d2c63e074152049c3f399d%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rd0774c95699d5aeb5e16e9a600fb2ea296e81175e30a62094e27e3e7%40%3Ccommits.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://lists.apache.org/thread.html/r74328b178f9f37fe759dffbc9c1f2793e66d79d7a8a20d3836551794%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rce2af55f6e144ffcdc025f997eddceb315dfbc0b230e3d750a7f7425%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rad36ec6a1ffc9e43266b030c22ceeea569243555d34fb4187ff08522%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rb2fc890bef23cbc7f343900005fe1edd3b091cf18dada455580258f9%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r38a5b7943b9a62ecb853acc22ef08ff586a7b3c66e08f949f0396ab1%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r17aaa3a05b5b7fe9075613dd0c681efa60a4f8c8fbad152c61371b6e%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rd50baccd1bbb96c2327d5a8caa25a49692b3d68d96915bd1cfbb9f8b%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r4afa11e0464408e68f0e9560e90b185749363a66398b1491254f7864%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r772335e6851ad33ddb076218fa4ff70de1bf398d5b43e2ddf0130e5d%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/re5eecbe5bf967439bafeeaa85987b3a43f0e6efe06b6976ee768cde2%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r5e2f1201b92ee05a0527cfc076a81ea0c270be299b87895c0ddbe02b%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r549b43509e387a42656f0641fa311bf27c127c244fe02007d5b8d6f6%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r61f280a76902b594692f0b24a1dbf647bb5a4c197b9395e9a6796e7c%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r4f86cb260196e5cfcbbe782822c225ddcc70f54560f14a8f11c6926f%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r9f119d9ce9239114022e13dbfe385b3de7c972f24f05d6dbd35c1a2f%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r089dc67c0358a1556dd279c762c74f32d7a254a54836b7ee2d839d8e%40%3Cdev.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rbdb1d2b651a3728f0ceba9e0853575b6f90296a94a71836a15f7364a%40%3Cdev.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2%40%3Cdev.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rf26663f42e7f1a1d1cac732469fb5e92c89908a48b61ec546dbb79ca%40%3Cbugs.httpd.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://security.gentoo.org/glsa/202003-43","source_type":"MISC","tags":[]},{"url":"https://lists.apache.org/thread.html/rcd5cd301e9e7e39f939baf2f5d58704750be07a5e2d3393e40ca7194%40%3Ccommits.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://lists.apache.org/thread.html/rf992c5adf376294af31378a70aa8a158388a41d7039668821be28df3%40%3Ccommits.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://lists.apache.org/thread.html/r6a5633cad1b560a1e51f5b425f02918bdf30e090fdf18c5f7c2617eb%40%3Ccommits.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2XFLQB3O5QVP4ZBIPVIXBEZV7F2R7ZMS/","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L46WJIV6UV3FWA5O5YEY6XLA73RYD53B/","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/K3IPNHCKFVUKSHDTM45UL4Q765EHHTFG/","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r43faacf64570b1d9a4bada407a5af3b2738b0c007b905f1b6b608c65%40%3Cusers.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00002.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://www.debian.org/security/2020/dsa-4673","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.debian.org/security/2020/dsa-4680","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/ra7092f7492569b39b04ec0decf52628ba86c51f15efb38f5853e2760%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r8f7484589454638af527182ae55ef5b628ba00c05c5b11887c922fb1%40%3Cnotifications.ofbiz.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20200226-0002/","source_type":"MISC","tags":[]},{"url":"http://support.blackberry.com/kb/articleDetail?articleNumber=000062739","source_type":"MISC","tags":[]},{"url":"https://lists.apache.org/thread.html/r92d78655c068d0bc991d1edbdfb24f9c5134603e647cade1113d4e0a%40%3Cusers.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2%40%3Cissues.geode.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://lists.apache.org/thread.html/r57f5e4ced436ace518a9e222fabe27fb785f09f5bf974814cc48ca97%40%3Ccommits.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://lists.apache.org/thread.html/r47caef01f663106c2bb81d116b8380d62beac9e543dd3f3bc2c2beda%40%3Ccommits.tomee.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list","patch"]},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://lists.apache.org/thread.html/r90890afea72a9571d666820b2fe5942a0a5f86be406fa31da3dd0922%40%3Cannounce.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/r1125f3044a0946d1e7e6f125a6170b58d413ebd4a95157e4608041c7%40%3Cannounce.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]}],"timeline":[{"type":"exploit_known","at":"2020-02-20T00:00:00Z","label":"Public exploit available","source":"exploit-db"},{"type":"published","at":"2020-02-24T21:19:18Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2022-03-03T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"poc_available","at":"2026-06-24T00:29:48.638073Z","label":"Public PoC available","source":"nuclei"},{"type":"ssvc_changed","at":"2026-06-24T00:31:28.220836Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:28.220836Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:31:28.220836Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:28.220836Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:28.220836Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:31:28.220836Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"started_trending","at":"2026-08-26T01:37:50.373238Z","label":"Started trending","source":null}]}