Skip to main content

Port Details

Port
8009
Transport
TCP
Service
AJP
IANA service name
nvme-disc
Range
User port (1024-49151)
Related ports

Security Exposure

Tomcat treats AJP connections as more trusted than HTTP, and AJP is a cleartext protocol. Before Tomcat 9.0.31, 8.5.51 and 7.0.100, the AJP connector was enabled by default on all addresses. CVE-2020-1938 (Ghostcat) allowed reading files from the web application and, with file upload, remote code execution when the AJP port was reachable, and it is in the CISA KEV catalog.

Hardening

  • +Remove the AJP connector from server.xml if no front-end web server uses it.
  • +Bind the AJP connector to localhost or the proxy's private address with the address attribute.
  • +Set secretRequired and a secret shared with the front-end proxy.
  • +Upgrade Tomcat to releases with the hardened AJP defaults.
  • +Block TCP 8009 at the firewall from all hosts except the front-end proxy.

Monitoring

Alert on connections to TCP 8009 from any address other than the configured reverse proxy and on Tomcat listening on 8009 on public interfaces.

AJP Vulnerabilities

1 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2020-1938
Apache Tomcat Improper Privilege Management Vulnerability
Apache9.899.3%KEV2020-02-24

Tools for Auditing and Monitoring AJP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is Ghostcat?→

Ghostcat is CVE-2020-1938, an AJP flaw in Apache Tomcat that allowed file reads and possible remote code execution when the AJP port was reachable by untrusted users.

Do I need port 8009 open?→

Only if a front-end web server forwards requests to Tomcat over AJP. Tomcat's security guide says AJP connectors should normally only be used on trusted networks.

Which vulnerabilities affect the service on port 8009?→

This database lists 1 CVE related to AJP, 1 of them confirmed as exploited by CISA. Examples: CVE-2020-1938.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8009 is not guaranteed to be AJP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).