← Back

CVE-2020-9484

Published: May 20, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.0 / Impact: 5.9
Source: NVD

Description

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

Affected (77)

Products: Apache: Tomcat · Debian: Debian Linux · Opensuse: Leap · +4 more
Show all products
1 product
Tomcat
1 product
Debian Linux
1 product
Leap
1 product
Fedora
1 product
Ubuntu Linux
20 products
Agile Engineering Data Management
Agile Plm
Communications Element Manager
Database
Fmw Platform
Hospitality Guest Access
Instantis Enterprisetrack
Managed File Transfer
Mysql Enterprise Monitor
Retail Order Broker
Siebel Apps Marketing
Siebel Ui Framework
Transportation Management
Workload Manager
1 product
Epolicy Orchestrator
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 7.0.0 to 7.0.108
From 8.5.0 to 8.5.63
From 9.0.1 to 9.0.43
Version 10.0.0 milestone1
Version 10.0.0 milestone2
Version 10.0.0 milestone3
Version 10.0.0 milestone4
Version 9.0.0 milestone10
Version 9.0.0 milestone11
Version 9.0.0 milestone12
Version 9.0.0 milestone13
Version 9.0.0 milestone14
Version 9.0.0 milestone15
Version 9.0.0 milestone16
Version 9.0.0 milestone17
Version 9.0.0 milestone18
Version 9.0.0 milestone19
Version 9.0.0 milestone1
Version 9.0.0 milestone20
Version 9.0.0 milestone21
Version 9.0.0 milestone22
Version 9.0.0 milestone23
Version 9.0.0 milestone24
Version 9.0.0 milestone25
Version 9.0.0 milestone26
Version 9.0.0 milestone27
Version 9.0.0 milestone2
Version 9.0.0 milestone3
Version 9.0.0 milestone4
Version 9.0.0 milestone5
Version 9.0.0 milestone6
Version 9.0.0 milestone7
Version 9.0.0 milestone8
Version 9.0.0 milestone9
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 8.0
Version 9.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 31
Version 32
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 16.04
Version 20.04
Configuration F
29 vulnerable
Configuration G
6 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Version 5.10.0
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.9.0
Version 5.9.1

References (84)

Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.