S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2018-11759 Scanner

CVE-2018-11759 scanner - Path Traversal vulnerability in Apache Software Foundation Apache Tomcat Connectors

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-11759
7.5
CVSS

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Tomcat Connectorsby Apache Software Foundation
Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44
Updated Aug 21, 2026View on NVD →
Detail

Apache Tomcat Connectors software is a tool that enables communication between Apache HTTP Server and Apache Tomcat, facilitating web application server configuration. The purpose of the software is to provide users with simplicity and ease of use, allowing for swift integration of the Apache HTTP Server and Apache Tomcat. The software is primarily used in a production environment, enabling organizations to optimize their web applications for better performance.

CVE-2018-11759 is a vulnerability discovered in the Apache Tomcat Connectors software. In earlier versions of the software, the code that normalized requested paths wasn't programmed to handle every possible scenario. This resulted in certain edge cases not being handled correctly. An attacker could exploit this vulnerability by submitting specially crafted requests that would expose critical application functionality unintended for client access. The vulnerability could also bypass implemented access controls in some settings.

If exploited, this CVE-2018-11759 vulnerability could have serious ramifications for an organization's digital assets. A cyber attacker could gain access to sensitive data, leading to theft, data breaches, and other malicious activities. Exploitation of this vulnerability would result in a major security incident, jeopardizing the confidentiality, integrity, and availability of affected systems.

Thanks to the pro features of s4e.io, users can stay informed about potential vulnerabilities in their digital assets. Our advanced platform provides accurate analysis and real-time threat detection, enabling swift action to protect your digital assets from online threats. Sign up today to ensure complete security for your organization's digital assets.

 

REFERENCES

Solution Advice

Precautions that can be taken to protect against this vulnerability include:

  • Updating the Apache Tomcat Connectors software to the latest version
  • Configuring HTTP server access controls to block malicious requests
  • Implementing web application firewall protections
  • Regularly monitoring logs for suspicious activity
  • Regularly auditing and scanning systems for vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-11759 scanner - Path Traversal vulnerability in Apache Software Foundation Apache Tomcat Connectors S4E