CVE-2020-1745
Java vulnerability analysis and mitigation

Overview

A file inclusion vulnerability (CVE-2020-1745) was discovered in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and earlier versions, which was fixed in version 2.0.30.Final. The vulnerability was reported to the Apache Software Foundation on January 3, 2020 (Red Hat Bugzilla).

Technical details

The vulnerability exists in the AJP (Apache JServ Protocol) connector, which is enabled by default on port 8009. The CVSS v3.1 base score is 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The vulnerability allows an unauthenticated remote attacker to read web application files from a vulnerable server through the AJP protocol functionality (NetApp Security, Tenable Blog).

Impact

A successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution (NVD, NetApp Security).

Exploitability

The vulnerability can be exploited by a remote, unauthenticated attacker who can reach the AJP port directly. Several proof-of-concept exploit scripts have been made publicly available. The vulnerability is particularly dangerous because AJP is enabled by default and assumes that the network is safe (Tenable Blog).

Mitigation and workarounds

If patching is not feasible, there are several mitigation options: 1) Disable AJP altogether if not in use by commenting it out from the configuration file, 2) Configure a secret password for the AJP conduit using the requiredSecret attribute, or 3) Ensure proper firewall rules are in place to restrict access to the AJP port. The recommended solution is to upgrade to Undertow version 2.0.30.Final or later (Red Hat Solution).

Community reactions

The vulnerability has received significant attention from the security community, with researchers confirming its potential for both file read and remote code execution capabilities. Security researchers from various organizations, including Alibaba Cloud and others, have publicly demonstrated and discussed the vulnerability's impact (Tenable Blog).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-73644CRITICAL9.6
  • Java logoJava
  • org.openidentityplatform.opendj:opendj-server-legacy
NoYesAug 13, 2026
CVE-2026-73507HIGH7.5
  • Java logoJava
  • datahub-upgrade
NoYesAug 13, 2026
CVE-2026-49989HIGH7.1
  • Java logoJava
  • io.crate:crate
NoYesAug 14, 2026
CVE-2026-53660HIGH7
  • Java logoJava
  • org.openidentityplatform.openam:openam-core
NoYesAug 14, 2026
CVE-2026-73508MEDIUM5.3
  • Java logoJava
  • camunda-zeebe-8.8
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management