Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libapache-mod-jk | Jul 30, 2024 | Mar 4, 2007 |
| Freebsd | — | Upgrade mod_jk-ap2Upgrade mod_jk | Dec 10, 2025 | Mar 5, 2007 |
| Gentoo Linux | — | Upgrade www-apache/mod_jk. | Oct 30, 2017 | Mar 4, 2007 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Aug 11, 2017 | Mar 4, 2007 |
| Suse | — | Upgrade apache2-mod_jk | Aug 9, 2024 | Mar 4, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub