Port 8009: Apache JServ Protocol (AJP13)
Port 8009 is the default port for AJP13, the binary protocol that web servers such as Apache httpd use to forward requests to Apache Tomcat. The mod_jk documentation sets 8009 as the default for ajp13 workers, and mod_proxy_ajp examples use ajp://backend:8009. IANA assigns TCP 8009 to nvme-disc (NVMe over Fabrics Discovery), which differs from this common use.
Port Details
Security Exposure
Tomcat treats AJP connections as more trusted than HTTP, and AJP is a cleartext protocol. Before Tomcat 9.0.31, 8.5.51 and 7.0.100, the AJP connector was enabled by default on all addresses. CVE-2020-1938 (Ghostcat) allowed reading files from the web application and, with file upload, remote code execution when the AJP port was reachable, and it is in the CISA KEV catalog.
Hardening
- +Remove the AJP connector from server.xml if no front-end web server uses it.
- +Bind the AJP connector to localhost or the proxy's private address with the address attribute.
- +Set secretRequired and a secret shared with the front-end proxy.
- +Upgrade Tomcat to releases with the hardened AJP defaults.
- +Block TCP 8009 at the firewall from all hosts except the front-end proxy.
Monitoring
Alert on connections to TCP 8009 from any address other than the configured reverse proxy and on Tomcat listening on 8009 on public interfaces.
AJP Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2020-1938 | Apache Tomcat Improper Privilege Management Vulnerability | Apache | 9.8 | 99.3% | KEV | 2020-02-24 |
Tools for Auditing and Monitoring AJP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is Ghostcat?→
Ghostcat is CVE-2020-1938, an AJP flaw in Apache Tomcat that allowed file reads and possible remote code execution when the AJP port was reachable by untrusted users.
Do I need port 8009 open?→
Only if a front-end web server forwards requests to Tomcat over AJP. Tomcat's security guide says AJP connectors should normally only be used on trusted networks.
Which vulnerabilities affect the service on port 8009?→
This database lists 1 CVE related to AJP, 1 of them confirmed as exploited by CISA. Examples: CVE-2020-1938.
Sources
- IANA Service Name and Transport Protocol Port Number Registry: 8009
- Apache Tomcat Connectors: workers.properties reference
- Apache HTTP Server: mod_proxy_ajp
- Apache Tomcat 9 Configuration Reference: The AJP Connector
- Apache Tomcat 9: Security Considerations
- Apache Tomcat 9.x security vulnerabilities
- NVD: CVE-2020-1938
- Tenable: CVE-2020-1938: Ghostcat - Apache Tomcat AJP File Read/Inclusion Vulnerability
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8009 is not guaranteed to be AJP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).