Security readout for executives and security teams
Plain-English summary
This issue affects Apache Tomcat systems where the AJP connector is reachable by untrusted users. AJP was treated as more trusted than HTTP, and vulnerable defaults exposed it broadly. Attackers with network access to AJP could read application files and, in specific upload/control scenarios, potentially execute code.
Executive priority
Treat as urgent where vulnerable Tomcat has reachable AJP. The business risk is unauthorized file access and possible server compromise. Prioritize externally reachable systems first, then shared internal networks, development environments, and packaged applications embedding Tomcat.
Technical view
CVE-2020-1938 is an AJP request injection and potential remote code execution flaw in Apache Tomcat 9.0.0.M1-9.0.0.30, 8.5.0-8.5.50, and 7.0.0-7.0.99. Exposure depends on whether the AJP port is accessible to untrusted users. Apache states fixed versions include 9.0.31, 8.5.51, and 7.0.100 or later.
Likely exposure
Highest exposure is vulnerable Tomcat with AJP enabled and reachable from the internet, partner networks, shared hosting, or broad internal networks. Systems with AJP disabled or restricted to trusted front-end servers are materially less exposed, based on the supplied Apache guidance.
Exploitation context
The supplied sources do not show CISA KEV listing or confirmed active exploitation. The described impact is severe because reachable AJP can expose web application files and may enable code execution if an attacker can place or control content processed as JSP.
Researcher notes
The key exposure condition is network reachability of AJP, not merely running Tomcat. RCE requires an additional condition: attacker-controlled content inside the web application or another way to control web application content. Evidence in the bundle supports upgrade and AJP hardening, but not active exploitation claims.
Mitigation direction
- Upgrade Tomcat to 9.0.31, 8.5.51, 7.0.100, or later.
- Disable the AJP connector if it is not required.
- Restrict AJP access to trusted front-end servers only.
- Review Tomcat AJP configuration after upgrading, because defaults changed.
- Check vendor or distribution guidance for packaged Tomcat builds.
Validation and detection
- Inventory Apache Tomcat versions across production and internal environments.
- Confirm whether AJP is enabled on each Tomcat instance.
- Verify AJP is not reachable from untrusted networks.
- Review applications for upload paths stored inside the web application.
- Confirm upgraded instances still have intended front-end proxy behavior.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupFile access behavior lookup
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-1938 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Critical
- CVSS
- 9.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
9.8CriticalVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source materials
- CVE List V5 sourceCVE List V5
- [tomcat-announce] 20200224 [SECURITY] CVE-2020-1938 AJP Request Injection and potential Remote Code ExecutionCVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-notifications] 20200225 [jira] [Commented] (OFBIZ-11407) Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938)CVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-notifications] 20200225 [jira] [Updated] (OFBIZ-11407) Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938)CVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-commits] 20200227 [ofbiz-plugins] branch release17.12 updated: Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938) (OFBIZ-11407)CVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-notifications] 20200227 [jira] [Commented] (OFBIZ-11407) Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938)CVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-notifications] 20200228 [jira] [Commented] (OFBIZ-11407) Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938)CVE reference · mailing-list, x_refsource_MLIST
- [ofbiz-notifications] 20200228 [jira] [Comment Edited] (OFBIZ-11407) Upgrade Tomcat from 9.0.29 to 9.0.31 (CVE-2020-1938)CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200301 Re: [SECURITY] CVE-2020-1938 AJP Request Injection and potential Remote Code ExecutionCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200302 Re: AW: [SECURITY] CVE-2020-1938 AJP Request Injection and potentialRemote Code ExecutionCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200302 AW: [SECURITY] CVE-2020-1938 AJP Request Injection and potentialRemote Code ExecutionCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200302 Re: [SECURITY] CVE-2020-1938 AJP Request Injection and potential Remote Code ExecutionCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200304 Re: Fix for CVE-2020-1938CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-dev] 20200304 Re: Tagging 10.0.x, 9.0.x, 8.5.xCVE reference · mailing-list, x_refsource_MLIST
- [debian-lts-announce] 20200304 [SECURITY] [DLA 2133-1] tomcat7 security updateCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200305 Aw: Re: Fix for CVE-2020-1938CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200305 Re: Aw: Re: Fix for CVE-2020-1938CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-dev] 20200309 [Bug 64206] Answer file not being usedCVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200309 Re: Apache Tomcat AJP File Inclusion Vulnerability (unauthenticated check)CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200310 Aw: Re: Re: Fix for CVE-2020-1938CVE reference · mailing-list, x_refsource_MLIST
- [tomcat-users] 20200310 Re: Re: Re: Fix for CVE-2020-1938CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20200311 CVE-2020-1938 on Tomcat 9.0.30 / TomEE 8.0.1CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20200311 Re: CVE-2020-1938 on Tomcat 9.0.30 / TomEE 8.0.1CVE reference · mailing-list, x_refsource_MLIST
- [tomee-dev] 20200316 RE: CVE-2020-8840 on TomEE 8.0.1CVE reference · mailing-list, x_refsource_MLIST
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
