Remediating Apache Tomcat AJP Connector Vulnerability (CVE-2020-1938) in iDash
search cancel

Remediating Apache Tomcat AJP Connector Vulnerability (CVE-2020-1938) in iDash

book

Article ID: 448025

calendar_today

Updated On:

Products

iDash Workload Automation

Issue/Introduction

Customers may identify CVE-2020-1938 (also known as Ghostcat) during security scans of their iDash Workload Automation environment. This vulnerability affects the Apache Tomcat AJP connector and could potentially allow an attacker to read or write files to the Tomcat server.

Resolution

The vulnerability is officially resolved in Apache Tomcat 9.0.31 and all subsequent versions.

  • Broadcom recommends upgrading to the latest supported version of iDash (such as 12.1.02.03 or higher), which bundles a secure version of Tomcat (e.g., v9.0.104).
  • Upgrading to any version greater than 9.0.31 will effectively patch the CVE-2020-1938 issue.