Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22687
HistoryMar 13, 2020 - 12:44 a.m.

Directory Traversal

2020-03-1300:44:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.01 Low

EPSS

Percentile

83.8%

undertow is vulnerable to directory traversal attacks. The vulnerability exists due to input validation error in AJP connector. A remote attacker can send a specially crafted HTTP request to port 8009/tcp and read arbitrary files on the system.