CVE-2020-1938Exploit(apache / agile_engineering_data_management)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for apache agile_engineering_data_management systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-03-17. Apply updates per vendor instructions.

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agile_engineering_data_management
  • agile_product_lifecycle_management
  • communications_element_manager
  • communications_instant_messaging_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-20); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Products
agile_engineering_data_managementagile_product_lifecycle_managementcommunications_element_managercommunications_instant_messaging_serverdata_availability_servicesdebian_linuxfedorageodegood_controlhealth_sciences_empirica_inspections

28 versions affected across 21 products

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-20: 1Mentions · 2026-04-02: 1Mentions · 2026-04-29: 1Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Mentions · 2026-08-28: 1PoC Mentioned / Linked · 2026-02-20: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-07-04: 1PoC Mentioned / Linked · 2026-08-28: 1Exploit Tool / Code · 2026-02-20: 1Exploit Tool / Code · 2026-08-28: 1Active Exploitation · 2026-08-28: 1Technical Details · 2026-08-28: 102-2004-0204-2907-0307-0408-28
Signal classification2 categories
Exploit
466.7%
General
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-201
Exploit1
2026-04-021
Exploit1
2026-04-291
General1
2026-07-031
General1
2026-07-041
Exploit1
2026-08-281
Exploit1
Full discourse6 posts
  • AkatsukiLegion@_AkatsukiLegion
    Exploit

    https://ghostcat2.py exploits #CVE-2020-1938 (#Tomcat AJP) for file reads. Combined with https://chain.py mapping internal IPs and routes for /sql, /ldap, /vdi. They were mapping the network. Targeted intrusion. https://t.co/SQ9vmusAqf

    Post summary

    The text references a Python PoC for CVE‑2020‑1938 and indicates that attackers used it in a targeted intrusion that involved internal network mapping.

    11040183
    205 followersView on X
  • tin3r@tin3r_
    Exploit

    Nuevo writeup en Lathack 🚀 Temas principales: ☕ Apache Tomcat 📡 AJP 8009 🐈 Ghostcat CVE-2020-1938 📦 WAR reverse shell 🔓 John + shadow backup ⬆️ Java/JAR PrivEsc 🔗 https://lathack.com/ctf/maquina-vulnnet-dotjar-de-tryhackme/ #TryHackMe #CTF #Pentesting #CyberSecurity

    Post summary

    The post announces a Lathack writeup on Ghostcat (CVE‑2020‑1938) in Apache Tomcat, outlining steps like a WAR‑based reverse shell, but it does not present explicit exploit code or evidence of active exploitation.

    0001080
    25 followersView on X
  • pentestTeam@TeamPentest
    General

    Recon → root → a full OSCP-style report in 8 minutes. An AI assistant runs the whole lab engagement with you: nmap, Ghostcat (CVE-2020-1938), priv-esc to root, findings auto-logged. Ethical hacking practice, done smarter. 🧠 #oscp #ethicalhacking https://t.co/PuP2nAiiWu

    Post summary

    The post highlights an AI assistant for automated ethical hacking exercises, mentioning Ghostcat (CVE‑2020‑1938) but providing no PoC, exploit details, active exploitation evidence, patches, or technical depth.

    00010113
    9 followersView on X
  • Thinkkun@think_kun
    General

    Port 8080 open? Cool. Apache Tomcat 9.0.31? Now check CVE-2020-1938. Active recon isn't just finding open ports -- it's version detection that maps to real CVEs. nmap -sV --version-intensity 5 target #Pentesting #Infosec #Cybersecurity #Security #SysAdmin #Linux #DevSecOps

    Post summary

    The tweet highlights that Tomcat 9.0.31 is associated with CVE-2020-1938 and encourages using nmap for version detection but offers no further technical detail or actionable information.

    0001056
    26 followersView on X
  • 49@MDPorsch
    Exploit

    Then came manual validation. No blind trust in automated severity ratings. Every critical finding had to be proven. On Metasploitable 2, I exploited Ghostcat (CVE-2020-1938) on Port 8009 using Metasploit. https://t.co/9K5auyK4rt

    Post summary

    The post documents a successful exploitation of Ghostcat (CVE-2020-1938) on Metasploitable 2 using Metasploit, confirming the vulnerability's exploitability in a lab environment.

    1000037
    402 followersView on X
  • Havij@_havij
    Exploit

    [Tomghost] Apache Tomcat Ghostcat Exploit (CVE-2020-1938) to Root via AJP Misconfiguration Link: https://meetcyber.net/tomghost-apache-tomcat-ghostcat-exploit-cve-2020-1938-to-root-via-ajp-misconfiguration-b0122b33d881 #apache #apachetomcat #ghostcatexploit #cve20201938 #tryhackme https://t.co/OcU0d2joO8

    Post summary

    The post announces a root-level exploit for CVE‑2020‑1938 via an AJP misconfiguration, linking to a resource that likely contains the PoC, but it does not provide code, indicate active exploitation, or mention a patch.

    0000040
    25 followersView on X
CPE platform detail35 entries

35 of 35 entries

PartVendorProductVersionTarget SWTarget HW
Appapachegeode1.12.0--
Appapachetomcat---
Appblackberrygood_control---
Appblackberryworkspaces_server7.0.1--
Appblackberryworkspaces_server7.1.2--
Appblackberryworkspaces_server8.1.0--
Appblackberryworkspaces_server9.0--
OSdebiandebian_linux10.0--
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
OSfedoraprojectfedora30--
OSfedoraprojectfedora31--
OSfedoraprojectfedora32--
Appnetappdata_availability_services---
Appnetapponcommand_system_manager---
OSopensuseleap15.1--
Apporacleagile_engineering_data_management6.2.1.0--
Apporacleagile_product_lifecycle_management9.3.3--
Apporacleagile_product_lifecycle_management9.3.5--
Apporacleagile_product_lifecycle_management9.3.6--
Apporaclecommunications_element_manager8.1.1--
Apporaclecommunications_element_manager8.2.0--
Apporaclecommunications_element_manager8.2.1--
Apporaclecommunications_instant_messaging_server10.0.1.4.0--
Apporaclehealth_sciences_empirica_inspections1.0.1.2--
Apporaclehealth_sciences_empirica_signal7.3.3--
Apporaclehospitality_guest_access4.2.0--
Apporaclehospitality_guest_access4.2.1--
Apporacleinstantis_enterprisetrack---
Apporaclemysql_enterprise_monitor---
Apporaclesiebel_ui_framework---
Apporacletransportation_management6.3.7--
Apporacleworkload_manager12.2.0.1--
Apporacleworkload_manager18c--
Apporacleworkload_manager19c--

Explore more