CVE-2018-11759

HIGH EXPLOITED NUCLEI LAB

Apache Tomcat JK Connector 1.2.0-1.2.44 - Path Traversal via Request Path Normalization

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-11759 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 3 public exploits from researchers including immunIT, Jul10l1r4, julioliraup. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC demonstrates an access bypass vulnerability in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44, where a semicolon in the URL path can bypass restrictions on protected endpoints like the JK status manager interface.

Description

The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was also possible in some configurations for a specially constructed request to bypass the access controls configured in httpd. While there is some overlap between this issue and CVE-2018-1323, they are not identical.

Exploits (3)

nomisec WORKING POC 40 stars
by immunIT · poc
https://github.com/immunIT/CVE-2018-11759

This PoC demonstrates an access bypass vulnerability in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44, where a semicolon in the URL path can bypass restrictions on protected endpoints like the JK status manager interface.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44
No auth needed
Prerequisites: Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 · Access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER 5 stars
by Jul10l1r4 · poc
https://github.com/Jul10l1r4/Identificador-CVE-2018-11759

This repository contains a bash script designed to check if instances are vulnerable to CVE-2018-11759. It audits target load balancers and collects details such as internal addresses, ports, and timestamps.

Classification
Scanner 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Traffic Server (versions affected by CVE-2018-11759)
No auth needed
Prerequisites: Target URLs with complete addresses including protocol
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec SCANNER
by julioliraup · poc
https://github.com/julioliraup/Identificador-CVE-2018-11759

This repository provides a bash script to check if instances are vulnerable to CVE-2018-11759, an information disclosure vulnerability in Apache Struts 2. It collects details about the target load balancer and saves them in a file for audit purposes.

Classification
Scanner 80%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apache Struts 2 (versions affected by CVE-2018-11759)
No auth needed
Prerequisites: Target URL with complete address including protocol
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Apache Tomcat JK Connect <=1.2.44 - Manager Access
HIGHby harshbothra_
Shodan: title:"Apache Tomcat" || http.title:"apache tomcat"
FOFA: title="apache tomcat"

References (13)

Core 13
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2018/dsa-4357
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0367
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105888
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/12/msg00007.html
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:0366

Scores

CVSS v3 7.5
EPSS 0.9418
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2023-12-19
CWE
CWE-22
Status published
Products (4)
apache/tomcat_jk_connector 1.2.0 - 1.2.44
debian/debian_linux 8.0
debian/debian_linux 9.0
redhat/jboss_core_services
Published Oct 31, 2018
Tracked Since Feb 18, 2026