Skip to main content
ExLibris

Knowledge Assistant

BETA
campusM

 

Ex Libris Knowledge Center
  1. Search site
    Go back to previous article
    1. Sign in
      • Sign in
      • Forgot password
  1. Home
  2. campusM
  3. Knowledge Articles
  4. CVE-2020-1938 Tomcat vulnerability

CVE-2020-1938 Tomcat vulnerability

  1. Last updated
  2. Save as PDF
  3. Share
    1. Share
    2. Tweet
    3. Share
  1. CVE-2020-1938 Tomcat vulnerability

CVE-2020-1938 Tomcat vulnerability

CVE-2020-1938 vulnerability was reported when using Apache JServ Protocol (AJP)

This Impacts Apache Tomcat 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 , Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses.

The campusM connect layer web services package is not expected to be affected by the tomcat upgrade but we would recommend follow the following steps :

  1. Backup existing tomcat installation, and configuration.
  2. On Sandbox/ Dev connect layer, upgrade from tomcat 7.x to 7.0.100 or 8.5.x to 8.5.51
  3. If the customer setup was reliant on an AJP connector to get through to tomcat from an upstream server, e.g. Apache, Load balancer etc, the AJP connector may need to be re-configured in tomcat server.xml, since the upgraded version of tomcat has this connector disabled by default.
  4. If configuring the tomcat upgrade separately, please ensure that the campusM web service packages (.war files) will need to be copied from webapps folder in the old tomcat installation folder into the new tomcat installation folder.
  5. Once completed, the customer can carry out a general app sanity test in their sandbox app instance, covering authentication and integrations reliant on the connect layer, e.g. timetable.

Once the functionality has been verified in sandbox, an upgrade of the production tomcat installation can be planned.

View article in the Exlibris Knowledge Center
  1. Back to top
    • Customer ability to close Salesforce Cases
    • Disabling TLS 1.0 and TLS 1.1 Encryption Protocols
  • Was this article helpful?

Recommended articles

  1. Article type
    Guide
    Content Type
    Knowledge Article
    Language
    English
    Product
    campusM
  2. Tags
    1. Connect layer
  1. © Copyright 2025 Ex Libris Knowledge Center
  2. Powered by CXone Expert ®
  • Term of Use
  • Privacy Policy
  • Contact Us
2025 Ex Libris. All rights reserved