Path traversal in Apache Tomcat JK ISAPI Connector - CVE-2018-11759

 

Path traversal in Apache Tomcat JK ISAPI Connector - CVE-2018-11759

Published: November 3, 2018 / Updated: April 7, 2020


Vulnerability identifier: #VU15703
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11759
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform path traversal attacks.

The vulnerability exists due to input validation error when matching requested path against URI-worker map in Apache Tomcat JK (mod_jk) Connector within the Apache Web Server (httpd) specific code. A remote attacker can send a specially crafted HTTP request to the affected system and expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy.


Affected software

Apache Tomcat JK ISAPI Connector
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Opensuse
Server Applications Module
openSUSE Leap
apache2-mod_jk-debuginfo
apache2-mod_jk-debugsource
apache2-mod_jk

How to mitigate CVE-2018-11759

Install updates from vendor's website.

Apache Tomcat JK ISAPI Connector - update to 1.2.46
apache2-mod_jk-debuginfo - update to 1.2.49-150100.6.6.1
apache2-mod_jk-debugsource - update to 1.2.49-150100.6.6.1
apache2-mod_jk - update to 1.2.49-150100.6.6.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins