Patch
CVE-2020-1938
with vRx
Vulnerability Overview
CVE Name
CVE-2020-1938
Severity
9.8
Critical
CVE Description
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker...
Show more
Show less
Latest Patch info
Patch Name
[tomcat-users] 20200310 Re: Re: Re: Fix for CVE-2020-1938
Date
11.11.2023
Script
.png)
Script Type
Remediation script
In cases where AJP Connector is not in use and Tomcat cannot be upgraded to a newer version, we can disable the vulnerable AJP connector by simply commenting it out of the config. This script searches the web.xml file for the relevant tag and comments it out as well as restarts the Tomcat service which is necessary for the mitigation to take effect.
Read more
Read less
Affected OS & Apps

Tomcat
by
Apache
Agile PLM
by
Oracle
Geode
by
Apache
Show more
Patch faster and smarter
with vRx
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Trusted by 600+ customers:




Solution
Patch faster and better with vRx
Patch Management
vRx automatically deploys patches across all systems, cutting patching time by 80%.
Scripting Engine
vRx’s scripting engine solves complex vulnerabilities, like log4j, with built-in or custom scripts.
Patchless Protection
vRx’s Patchless Protection secures vulnerable apps and reduces risk while maintaining functionality.

Automated Patching, Scripting, and more
Talk with our team to get a personal walkthrough
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.