446
VMScore

CVE-2018-1323

Published: 12/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat jk connector

Vendor Advisories

Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2423 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 120 to 1242 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose applicati ...

Github Repositories

Proof of concept showing how to exploit the CVE-2018-11759

CVE-2018-11759 Proof of concept Description The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 120 to 1244 did not handle some edge cases correctly If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially construc

Exploit Tomcat- Reverse Proxy

This is based on CVE-2018-11759 -Deserialization The Apache Web Server (httpd) specific code that normalized the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 120 to 1244 did not handle some edge cases correctly If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially con

CVE 2020-5902 Presented by: Tharmiga Loganathan, Manavjot Singh, Mili Choksi Vulnerability Highlights: CVSS 3x: 98 (Critical) CVSS 20: 100 (High) The CVE 2020-5902 vulnerability impacted F5 Network's suite of load-balancing software products called BIG-IP last July It is a code injection attack that can give hackers root level privileges to vulnerable systems! Accord