Description
The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via IIS, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing Tomcat via the reverse proxy.
In plain language
AI Worth attentionThis bug in the Apache Tomcat JK ISAPI Connector can let an attacker reach Tomcat application features they weren’t meant to reach; small businesses should worry if they run Tomcat behind IIS using this connector.
In Apache Tomcat JK ISAPI Connector versions 1.2.0 through 1.2.42, incorrect path normalization in the IIS/ISAPI handling can bypass URI-to-worker mapping for crafted requests, potentially exposing Tomcat application functionality that should only be reachable through the intended Tomcat paths.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-1323 and every CVE in our database. Create a free account — no credit card required.
Create Free Account