PT-2020-20694 · Apache · Apache Tomcat

Published

2020-11-22

·

Updated

2020-11-22

·

CVE-2020-948444

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Apache Tomcat (affected versions not specified)
Description The issue allows an attacker to potentially exploit a vulnerability by sending a crafted GET request to the /index.jsp API endpoint with a specifically designed Cookie header containing a JSESSIONID value set to ../../../../../usr/local/tomcat/groovy. This could lead to unauthorized access or other malicious activities. The estimated number of potentially affected devices worldwide is not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-948444

Affected Products

Apache Tomcat