Disclosure summary
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-03-03T00:00:00-05:00
MODIFIED 2022-03-03T00:00:00-05:00
INGESTED 2026-10-06T11:42:58-04:00