ENISA EUVD · EUVD-2020-0481Known-exploited evidence recordedWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Official EUVD record ↗BSI · German · WID-SEC-2024-0528Dell Data Protection Advisor: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Dell Data Protection Advisor ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Dateien zu manipulieren, vertrauliche Informationen offenzulegen, seine Berechtigungen zu erweitern oder einen nicht spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2023-2480Apache Tomcat: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des DienstesEin entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AV20-195IBM security advisoryOn 11 and 12 June 2020 IBM released security updates to address multiple vulnerabilities in the following products:
Vulnerabilities in third-party components, respectively Tomcat and Dojo, could allow a remote actor to execute or inject arbitrary code.
Official advisory ↗Canadian Centre for Cyber Security · English · AV20-077Red Hat security advisoryOn 17 March 2020 Red Hat released security advisories to address vulnerabilities affecting its operating system. Of note is a security update to Red Hat’s JBoss Web Server, which addresses vulnerabilities in a component of JBoss, namely, Apache Tomcat. The update includes a fix for the recently discovered ‘Ghostcat’ vulnerability, tracked as CVE-2020-1938.
Note to Readers
The Canadian Centre for Cyber Security (Cyber Centre) operates as part of the Communications Security Establishment. We are Canada’s national authority on cyber security and we lead the government’s response to cyber security events. As Canada's national computer security incident response team, the Cyber Centre works in close collaboration with government departments, critical infrastructure, Canadian businesses and international partners to prepare for, respond to, mitigate, and recover from cyber events. We do this by providing authoritative advice and support, and coordinating information sharing and incident response. The Cyber Centre is outward-facing, welcoming partnerships that help build a stronger, more resilient cyber space in Canada.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-435Multiples vulnérabilités dans Oracle MySQLd?id=CVE-2020-14643
Référence CVE CVE-2020-14651
https://www.cve.org/CVERecord?id=CVE-2020-14651
Référence CVE CVE-2020-14654
https://www.cve.org/CVERecord?id=CVE-2020-14654
Référence CVE CVE-2020-14656
https://www.cve.org/CVERecord?id=CVE-2020-14656
Référence CVE CVE-2020-14663
https://www.cve.org/CVERecord?id=CVE-2020-14663
Référence CVE CVE-2020-14678
https://www.cve.org/CVERecord?id=CVE-2020-14678
Référence CVE CVE-2020-14680
https://www.cve.org/CVERecord?id=CVE-2020-14680
Référence CVE CVE-2020-14697
https://www.cve.org/CVERecord?id=CVE-2020-14697
Référence CVE CVE-2020-14702
https://www.cve.org/CVERecord?id=CVE-2020-14702
Référence CVE CVE-2020-1938
https://www.cve.org/CVERecord?id=CVE-2020-1938
Référence CVE CVE-2020-1967
https://www.cve.org/CVERecord?id=CVE-2020-1967
Référence CVE CVE-2020-5258
https://www.cve.org/CVERecord?id=CVE-2020-5258
Référence CVE CVE-2020-5398
https://www.cve.org/CVERecord?id=CVE-2020-5398
Gestion détaillée du document
le 15 juillet 2020
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des systèm
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-350Multiples vulnérabilités dans les produits SAPDe multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquant de provoquer un
problème de sécurité non spécifié par l'éditeur, une exécution de code
arbitraire à distance et un contournement de la politique de sécurité.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-112Vulnérabilité dans Apache TomcatUne vulnérabilité a été découverte dans le connecteur AJP de Apache
Tomcat, qui est activé par défaut. Elle permet à un attaquant ayant la
capacité de se connecter directement sur le connecteur AJP de Tomcat de
provoquer une atteinte à la confidentialité des données.
Dans le cas où l'application propose une fonctionnalité de
téléchargement de fichier, un attaquant ayant accès à cette
fonctionnalité pourrait déposer du code exécutable JSP ( JavaServer
Pages ) et en déclencher l'exécution via la présente vulnérabilité.
Des premières preuves de concept ont été publiées, elles permettent
d'accéder à un fichier arbitraire au sein du répertoire d'exécution de
Apache Tomcat.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2020-001757Apache Tomcat の複数の脆弱性に対するアップデートThe Apache Software Foundation から、Apache Tomcat に関する次の複数の脆弱性に対するアップデートが公開されました。 * HTTP Request Smuggling (CWE-444) - CVE-2020-1935、CVE-2019-17569 * Apache Tomcat が無効な Transfer-Encoding ヘッダーを誤って処理したリバースプロキシの配下にある場合 HTTP Request Smuggling 攻撃を受ける可能性があります。 * 不適切な認可処理 (CWE-285) - CVE-2020-1938 * Apache JServ Protocol (AJP) は Apache httpd が受け付けたリクエストを Apache Tomcat に連携する際に使用されており、デフォルトで有効な設定となっています。AJP ポートにアクセスが可能な場合、任意のリクエストを送信される可能性があります。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5873최근 해킹 공격에 활용되는 취약점 보안 업데이트 권고격이 활발히 발생하고있어, 기업 담당자들의 철저한 사전 보안 점검 및 대비 필요
o 취약한 버전의 소프트웨어, 서버를 사용하는 기업 및 사용자는 최신버전으로 업데이트 권고
##### □ 최근 악용되고있는 주요 취약점
ㅇ Apache APISIX에서 발생하는 인증 우회 취약점(CVE-2021-45232)[1]
ㅇ Apache HTTP Server에서 경로 탐색(Path Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-42013)[2]
ㅇ Apache HTTP Server에서 경로 탐색(Path Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-41773)[3]
ㅇ Apache OFBiz에서 발생하는 크로스 사이트 스크립팅(XSS) 취약점(CVE-2020-9496)[4]
ㅇ Apache OFBiz에서 발생하는 역직렬화 취약점(CVE-2021-26295)[5]
ㅇ Apache Struts에서 발생하는 원격코드 실행 취약점(CVE-2020-17530)[6]
ㅇ Apache Struts에서 사용자 입력값 검증 미흡으로 발생하는 원격 코드 실행 취약점(CVE-2021-31805)[7]
ㅇ Apache Tomcat이 AJP request 메시지를 처리할 때, 메시지에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점(CVE-2020-1938)[8]
ㅇ Apache Log4j에서 발생하는 원격코드 실행 취약점(CVE-2021-44228)[9]
ㅇ Atlassian Confluence Server 및 Data Center에서 OGNL 인젝션으로 인해 발생하는 원격코드실행 취약점(CVE-2021-26084)[10]
ㅇ BIG-IP에서 iControl REST 인증 미흡으로 인해 발생하는 불충분한 인가 취약점(CVE-2022-1388)[11]
ㅇ BIG-IP, BIG-IQ의 iControl REST 인터페이스에서 발생하는 원격 코드 실행 취약점(CVE-2021-22986)[12]
ㅇ Grafana 소프트웨어에서 경로탐색(Directory Traversal)으로 인해 발생하는 정보노출 취약점(CVE-2021-43798)[13]
ㅇ Inspur ClusterEngine V4.0에서 발생하는 원격 코드 실행 취약점(CVE-2020-21224)[14]
ㅇ Oracle WebLogic Server에서 발생하는 원격 코드 실행 취약점(CVE-2021-2109)[15]
ㅇ SMBv3 프로토콜이 조작된 패킷을 처리할 때 버퍼오버플로우로 인해 발생하는 원격코드실행 취약점(CVE-2020-0796)[16]
ㅇ Spring Cloud Gateway에서 발생하는 원격코드 실행 취약점(CVE-2022-22947
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5251주요 보안 취약점 업데이트를 재확인 하세요!!1
네트워크
CVE-2019-15978 외 10개
Cisco
Data Center Network Manager
명령어 삽입 취약점 등
[1]
2
네트워크
CVE-2019-19781
Citrix
ADC, Gateway,SDWAN-WANOP
임의코드 실행 취약점
[2]
3
네트워크
CVE-2020-11896
Cisco
ASR 500,5500
원격코드 실행 취약점
[3]
4
운영체제
CVE-2020-7247
-
OpenSMTPD
원격코드 실행 취약점
[4]
5
운영체제
CVE-2020-0674
MS
인터넷 익스플로러
원격코드 실행 취약점
[5]
6
운영체제
CVE-2020-0688
MS
윈도우 Exchange 서버
원격코드 실행 취약점
[6]
7
운영체제
CVE-2020-0796
MS
윈도우
SMBv3 원격코드 실행 취약점
[7]
8
운영체제
CVE-2019-14287
유닉스/리눅스
-
sudo 명령어 취약점
[8]
9
운영체제
CVE-2020-1472
MS
윈도우 서버
Netlogon 권한상승 취약점
[9]
10
가상화
CVE-2020-3943 외 2개
VMware
vRealize Operations
임의코드 실행 취약점 등
[10]
11
가상화
CVE-2020-3952
VMware
vCenter Server
정보유노출 취약점
[11]
12
웹서버
CVE-2020-1938
Apache
Tomcat
원격코드 실행 취약점
[12]
13
보안솔루션
CVE-2020-7845
지란지교시큐리티
스팸스나이퍼
버퍼오버플로우 취약점
[13]
14
보안솔루션
CVE-2020-25043 외 11개
Kaspersky 등 7개사
백신프로그램
임의파일 삭제 취약점 등
[14]
15
원격협업
CVE-2020-6109 외 1개
Zoom
Zoom
임의파일 쓰기 취약점
[15]
16
원격협업
CVE-2020-8207
Citrix
Workspace
권한 상승 취약점
[16]
17
원격협업
CVE-2020-13699
Team Viewer
TeamViewer
원격코드 실행 취약점
[17]
18
IoT
CVE-2020-10173 외 10개
LG 등 9개사
공유기, IP카메라 등
악성코드 유포, DDoS
[18]
19
복합기
CVE-2018-5924
HP
HP DesignJet
원격코드 실행 취약점
[19]
20
솔루션
CVE-2019-0708 외 24개
MS 등 14개사
운영체제, 보안솔루션 등
임의코드 실행 취약점 등
[20]
21
솔루션
-
위즈베라
Veraport
설치프로그램을 악용한 악성코드 유포
[21]
22
솔루션
-
솔라윈즈
솔라윈즈 오리온
제품 업데이트 과정에서 악성코드 배포 가능
[22]
[참고사이트]
[1] tools.cisco.co
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5107Apache Tomcat AJP 취약점 보안 조치 권고(2차)Tomcat이 AJP request 메시지를 처리할 때, 메시지에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점(CVE-2020-1938)
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5098Apache Tomcat 취약점 보안 업데이트 권고 (1차)AJP 사용 시, AJP 요청 메시지에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점(CVE-2020-1938)
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0123Kwetsbaarheden verholpen in Oracle Database ProductenDe kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om een Denial-of-Service te veroorzaken of om ongeautoriseerde toegang te verkrijgen tot gevoelige gegevens en gegevens te manipuleren. Subcomponenten als de RDBMS Listener, Java VM, en andere componenten zijn specifiek kwetsbaar, met CVSS-scores variërend van 5.3 tot 7.5, wat duidt op een gematigd tot hoog risico.
Official advisory ↗