Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service.
This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix like systems is affected. Neither the ISAPI redirector nor mod_jk on Windows is affected.
Users are recommended to upgrade to version 1.2.50, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-mod_jk | Oct 10, 2024 | Sep 23, 2024 | |
| Debian | debian-upgrade-libapache-mod-jk | Oct 17, 2024 | Sep 23, 2024 | |
| Redhat_linux | redhat-upgrade-mod_jkredhat-upgrade-mod_jk-debuginforedhat-upgrade-mod_jk-debugsource | Oct 9, 2024 | Sep 23, 2024 | |
| Rocky_linux | rocky-upgrade-mod_jkrocky-upgrade-mod_jk-debuginforocky-upgrade-mod_jk-debugsource | May 8, 2025 | Sep 23, 2024 | |
| Suse | — | suse-upgrade-apache2-mod_jk | Dec 5, 2025 | Jan 14, 2025 |
| Ubuntu | ubuntu-pro-upgrade-libapache2-mod-jk | Jun 3, 2026 | Jun 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub