CVE-2007-1860General(apache / tomcat_jk_web_server_connector)

LOWCVSS 5.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat_jk_web_server_connector

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
tomcat_jk_web_server_connector

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-03: 102-03
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2007-1860 — Tencent Building, Kejizhongyi Avenue Visit -- https://cti.loginsoft.com/ip/43.130.139.136 #Loginsoft #Cytellite #Cybersecurity #CVE20071860 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/RTjAZtS7vV

    Post summary

    The tweet notes detection of CVE-2007-1860 but provides no further technical, exploit, or mitigation details.

    0000049
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat_jk_web_server_connector---

Explore more