[WID-SEC-2023-2337] Apache Tomcat mod_jk Connector: Schwachstelle ermöglicht Umgehung von Sicherheitsmaßnahmen oder Offenlegung von Informationen CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 12.09.2023 Stand UPDATE 24.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Windows Produktbeschreibung Apache Tomcat ist ein Web-Applikationsserver für verschiedene Plattformen. Produkte UPDATE 05.08.2024 EMC Avamar Dell NetWorker UPDATE 11.06.2024 Ubuntu Linux UPDATE 10.04.2024 SUSE Linux UPDATE 07.12.2023 Red Hat JBoss Core Services 1 Red Hat JBoss Core Services UPDATE 24.09.2023 Debian Linux 12.09.2023 Apache Tomcat Connector (mod_jk) <1.2.49 Angriff Angriff Ein entfernter anonymer Angreifer kann eine Schwachstelle in Apache Tomcat mod_jk Connector ausnutzen, um Sicherheitsmaßnahmen zu umgehen oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A vulnerability (CVSS 7.5) in the Apache Tomcat mod_jk Connector allows a remote anonymous attacker to bypass security measures or disclose sensitive information. Affected versions are Apache Tomcat Connector (mod_jk) prior to version 1.2.49. The advisory indicates a mitigation is available, but a specific fixed version is not stated.