CVE-2020-1938
Apache Tomcat Improper Privilege Management Vulnerability
9.8
CVSS 3.1
99.3 %
EPSS (current)
2022-03-03
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Apache / Tomcat
Published: 2020-02-24 · Due (CISA): 2022-03-17
CWE: – · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | network/cves/2020/CVE-2020-1938.yaml | Ghostcat - Apache Tomcat - AJP File Read/Inclusion Vulnerability | – |
| exploitdb | 48143 | Apache Tomcat - AJP 'Ghostcat File Read/Inclusion | 2020-02-20 |
| metasploit | auxiliary/admin/http/tomcat_ghostcat | auxiliary/admin/http/tomcat_ghostcat | 2020-02-20 |
| exploitdb | 49039 | Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit) | 2020-11-13 |
References only — no downloads or instructions.