Apache fixes dangerous RCE flaw in Tomcat application server

Vulnerability affects multiple versions of the software running on Windows

The Apache Software Foundation has issued an update for its Tomcat application server software addressing an important remote code execution vulnerability.

Developed and offered under open source licenses, Tomcat is a Servlet container for Java apps designed to provide a web server environment purely comprised of Java specifications and frameworks.

The flaw, designated as CVE-2019-0232, affects Tomcat versions 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93. The error is caused by a problem with how command line arguments are passed from the Java Runtime Environment to Windows, and affects instances of the CGI Servlet running on Windows with command line arguments enabled.

Although this vulnerability could allow hackers to remotely execute code on affected servers, its severity was designated as 'important' rather than 'critical', due to the fact that the Servlet in question is disabled by default, as is the option to enable command line arguments in later Tomcat versions.

The flaw was discovered and reported to Apache earlier this month by an unnamed security researcher, and was disclosed by the foundation following the release of the patches as part of Tomcat versions 9.0.19, 8.5.40 and 7.0.93.

Admins are urgently advised to patch any affected servers within their estates. Vulnerabilities in Apache software have led to a number of high-profile breaches, including the notorious Equifax hack, which was the result of an unpatched Apache Spark server.

Featured Resources

Five lessons learned from the pivot to a distributed workforce

Delivering continuity and scale with a remote work strategy

Download now

Connected experiences in a digital transformation

Enable businesses to meet the demands of the future

Download now

Simplify to secure

Reduce complexity by integrating your security ecosystem

Download now

Enhance the safety and security of your people, assets and operations

Enable a true vision of security with an engineered solution based on hyperconverged and storage platforms

Download now

Recommended

'Largest ever' Magecart hack compromises 2,000 online stores
hacking

'Largest ever' Magecart hack compromises 2,000 online stores

15 Sep 2020
Infocyte integrates with Palo Alto Networks Cortex XSOAR
cyber security

Infocyte integrates with Palo Alto Networks Cortex XSOAR

19 Aug 2020
The Ritz suffers data breach after hackers pose as staff
data breaches

The Ritz suffers data breach after hackers pose as staff

17 Aug 2020
Russia hacked Liam Fox's personal email to steal trade documents
phishing

Russia hacked Liam Fox's personal email to steal trade documents

4 Aug 2020

Most Popular

Accenture ploughs $3 billion into cloud migration support group
digital transformation

Accenture ploughs $3 billion into cloud migration support group

17 Sep 2020
Google Pixel 4a review: A picture-perfect package
Google Android

Google Pixel 4a review: A picture-perfect package

18 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020