← Vulnerability feed

Vulnerability record · CVE-2007-0774 · published 4 March 2007

CVE-2007-0774: Apache Tomcat JK Connector mod_jk URI Worker Map Stack Buffer Overflow

Apache · Tomcat Jk Web Server Connector

A stack-based buffer overflow exists in the map_uri_to_worker function of mod_jk.so in Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as shipped with Tomcat 4.1.34 and 5.5.20. A remote attacker can trigger the overflow by sending a long URL that is processed by the URI worker map routine, potentially leading to arbitrary code execution on the web server.

7.5 CVSS 2.0 High EPSS 82% · top 0.4%
7.5CVSS 2.0 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
50References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 2.0 score of 7.5 and very high EPSS probability indicate a serious remote code execution risk, though no KEV listing or known ransomware use is documented.

What it is

A stack-based buffer overflow exists in the map_uri_to_worker function of mod_jk.so in Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as shipped with Tomcat 4.1.34 and 5.5.20. A remote attacker can trigger the overflow by sending a long URL that is processed by the URI worker map routine, potentially leading to arbitrary code execution on the web server.

Impact

Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code with the privileges of the web server process. This can lead to full compromise of the affected host or service.

Attack surface

The flaw is reachable over the network via HTTP requests to a web server using the vulnerable mod_jk connector. No authentication or user interaction is required, as indicated by the CVSS vector AV:N/AC:L/Au:N.

Exploitation

The vulnerability is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is very high (0.81513, 99.6th percentile), indicating a strong likelihood of exploitation activity. A vendor advisory and patch reference are available.

What to do

  • Upgrade mod_jk to a version later than 1.2.20 or apply the vendor patch referenced in the Apache Tomcat changelog.
  • If immediate patching is not possible, restrict or filter HTTP requests with excessively long URI paths before they reach the mod_jk connector.
  • Deploy a web application firewall or reverse proxy rule to block malformed or oversized URLs targeting the JK connector.
  • Review and minimize exposure of the JK connector to untrusted networks where feasible.

Detection

  • Monitor web server and mod_jk logs for unusually long URL requests or URI patterns that could trigger the worker map routine.
  • Use network intrusion detection signatures for known exploit attempts against CVE-2007-0774.
  • Watch for unexpected process crashes or restarts of the web server that may indicate exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795
http://secunia.com/advisories/24398
http://secunia.com/advisories/24558
http://secunia.com/advisories/27037
http://secunia.com/advisories/28711
http://securitytracker.com/id?1017719
http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html Patch
http://tomcat.apache.org/security-jk.html
http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml
http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml
http://www.redhat.com/support/errata/RHSA-2007-0096.html
http://www.securityfocus.com/archive/1/461734/100/0/threaded
http://www.securityfocus.com/bid/22791
http://www.vupen.com/english/advisories/2007/0809
http://www.vupen.com/english/advisories/2007/3386
http://www.vupen.com/english/advisories/2008/0331
http://www.zerodayinitiative.com/advisories/ZDI-07-008.html Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/32794
https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org
https://lists.apache.org/thread.html/r5c616dfc49156e4b06ffab842800c80f4425924d0f20c452c127a53c%40%3Cdev.tomcat.apache.or
https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.or
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5513
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795
http://secunia.com/advisories/24398
http://secunia.com/advisories/24558
http://secunia.com/advisories/27037
http://secunia.com/advisories/28711
http://securitytracker.com/id?1017719
http://tomcat.apache.org/connectors-doc/miscellaneous/changelog.html Patch
http://tomcat.apache.org/security-jk.html
http://www.cisco.com/en/US/products/products_security_advisory09186a008093f040.shtml
http://www.gentoo.org/security/en/glsa/glsa-200703-16.xml
http://www.redhat.com/support/errata/RHSA-2007-0096.html
http://www.securityfocus.com/archive/1/461734/100/0/threaded
http://www.securityfocus.com/bid/22791
http://www.vupen.com/english/advisories/2007/0809
http://www.vupen.com/english/advisories/2007/3386

Track CVE-2007-0774 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-0774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.