Path traversal in Apache Tomcat JK ISAPI Connector - CVE-2018-11759
Published: November 3, 2018 / Updated: April 7, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform path traversal attacks.
The vulnerability exists due to input validation error when matching requested path against URI-worker map in Apache Tomcat JK (mod_jk) Connector within the Apache Web Server (httpd) specific code. A remote attacker can send a specially crafted HTTP request to the affected system and expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy.
Affected software
Debian Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Opensuse
Server Applications Module
openSUSE Leap
apache2-mod_jk-debuginfo
apache2-mod_jk-debugsource
apache2-mod_jk
How to mitigate CVE-2018-11759
apache2-mod_jk-debuginfo - update to 1.2.49-150100.6.6.1
apache2-mod_jk-debugsource - update to 1.2.49-150100.6.6.1
apache2-mod_jk - update to 1.2.49-150100.6.6.1