Customers may identify CVE-2020-1938 (also known as Ghostcat) during security scans of their iDash Workload Automation environment. This vulnerability affects the Apache Tomcat AJP connector and could potentially allow an attacker to read or write files to the Tomcat server.
The vulnerability is officially resolved in Apache Tomcat 9.0.31 and all subsequent versions.