CVE-2020-1938 | Apache Tomcat up to 7.0.99/8.5.50/9.0.30 AJP Connector Ghostcat input validation (CNVD-2020-10487 / EDB-48143)
A vulnerability was found in Apache Tomcat up to 7.0.99/8.5.50/9.0.30. It has been classified as critical. This affects an unknown part of the component AJP Connector. The manipulation leads to improper input validation (Ghostcat).
This vulnerability is uniquely identified as CVE-2020-1938. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.