7.0highHigh

CVE-2020-9484

Apache Tomcat

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is requires local access to the machine.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, an ordinary user account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
7.0 (v3.1)
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-502
Assigned by
security@apache.org

Dates

Published
2020-05-20
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Tomcat7.0.0 - 7.0.108, 8.5.0 - 8.5.63, 9.0.1 - 9.0.43, 9.0.0, 10.0.0
  • Debian Debian Linux8.0, 9.0, 10.0
  • Opensuse Leap15.1
  • Fedoraproject Fedora31, 32
  • Canonical Ubuntu Linux16.04, 20.04
  • Oracle Agile Engineering Data Management6.2.1.0
  • Oracle Agile Product Lifecycle Management9.3.3, 9.3.5, 9.3.6
  • Oracle Communications Cloud Native Core Binding Support Function1.10.0
  • Oracle Communications Cloud Native Core Policy1.14.0
  • Oracle Communications Diameter Signaling Router8.0.0.0 - 8.4.0.5
  • Oracle Communications Element Manager8.2.0 - 8.2.2
  • Oracle Communications Instant Messaging Server10.0.1.4.0

As listed in the NVD configuration data. Not a statement about your estate.

References