Apache fixes dangerous RCE flaw in Tomcat application server
Vulnerability affects multiple versions of the software running on Windows
The Apache Software Foundation has issued an update for its Tomcat application server software addressing an important remote code execution vulnerability.
Developed and offered under open source licenses, Tomcat is a Servlet container for Java apps designed to provide a web server environment purely comprised of Java specifications and frameworks.
The flaw, designated as CVE-2019-0232, affects Tomcat versions 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93. The error is caused by a problem with how command line arguments are passed from the Java Runtime Environment to Windows, and affects instances of the CGI Servlet running on Windows with command line arguments enabled.
Although this vulnerability could allow hackers to remotely execute code on affected servers, its severity was designated as 'important' rather than 'critical', due to the fact that the Servlet in question is disabled by default, as is the option to enable command line arguments in later Tomcat versions.
The flaw was discovered and reported to Apache earlier this month by an unnamed security researcher, and was disclosed by the foundation following the release of the patches as part of Tomcat versions 9.0.19, 8.5.40 and 7.0.93.
Admins are urgently advised to patch any affected servers within their estates. Vulnerabilities in Apache software have led to a number of high-profile breaches, including the notorious Equifax hack, which was the result of an unpatched Apache Spark server.
Four cyber security essentials that your board of directors wants to know
The insights to help you deliver what they needDownload now
Data: A resource much too valuable to leave unprotected
Protect your data to protect your companyDownload now
Improving cyber security for remote working
13 recommendations for security from any locationDownload now
Why CEOS should care about the move to SAP S/4HANA
And how they can accelerate business valueDownload now