S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-1335 Scanner

CVE-2018-1335 scanner - Directory Traversal vulnerability in Apache Tika

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-1335
8.1
CVSS

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Tikaby Apache Software Foundation
1.7 to 1.17
Updated Aug 18, 2026View on NVD →
Detail

Apache Tika is an open-source software tool that is used for detecting and extracting metadata and text from various file types such as documents, images, and audio files. This Java-based tool is designed to support different formats of files and extract information quickly and efficiently. The main purpose of Tika is to provide a uniform interface for extracting content and metadata from several sources to enable interoperability between various content management systems, file format viewers, or search engines.

The CVE-2018-1335 vulnerability was discovered in Apache Tika versions 1.7 to 1.17. This vulnerability allowed unauthenticated users to execute arbitrary commands using crafted headers sent to Tika Server. Attackers could potentially gain unauthorized access to the server and inject malicious code that could lead to data theft, denial of service attacks, or even complete server takeover. The vulnerability lies in the way Tika interacts with the command line, which makes it vulnerable to command injection attacks.

When this vulnerability is exploited, it could lead to severe consequences such as data breaches, unauthorized access to sensitive information, and potential reputational damage. If an attacker gains access to a company's server, they could potentially install malware, steal customer data, and even use the server as a platform to launch further attacks on other systems.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. With access to comprehensive vulnerability databases, advanced scanning, and reporting tools, users can quickly identify and address security vulnerabilities and minimize their exposure to cyber threats. Additionally, the platform provides regular updates and alerts on new vulnerabilities in popular software tools, making it easier to stay up-to-date on the latest threats.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Upgrade Apache Tika to version 1.18.
  • Implement network segmentation and firewall rules that limit access to Tika Servers.
  • Implement access control rules that limit the number of users who can access Tika Servers.
  • Ensure that Tika Server is not exposed to the public internet and is only accessible from trusted networks.
  • Implement intrusion detection and prevention systems that can detect and block malicious traffic before it reaches Tika Server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.