{"id":"CVE-2020-9484","title":"When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…","summary":"When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.0, < 7.0.108","tomcat >= 8.5.0, < 8.5.63","tomcat >= 9.0.1, < 9.0.43","tomcat = 9.0.0","tomcat = 10.0.0","debian_linux = 8.0","debian_linux = 9.0","debian_linux = 10.0","leap = 15.1","fedora = 31","fedora = 32","ubuntu_linux = 16.04","ubuntu_linux = 20.04","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","communications_cloud_native_core_binding_support_function = 1.10.0","communications_cloud_native_core_policy = 1.14.0","communications_diameter_signaling_router >= 8.0.0.0, <= 8.4.0.5","communications_element_manager >= 8.2.0, <= 8.2.2","communications_instant_messaging_server = 10.0.1.4.0","communications_session_report_manager >= 8.2.0, <= 8.2.2","communications_session_route_manager >= 8.2.0, <= 8.2.2","database = 12.2.0.1","database = 19c","database = 21c","fmw_platform = 12.2.1.3.0","fmw_platform = 12.2.1.4.0","hospitality_guest_access = 4.2.0","hospitality_guest_access = 4.2.1","instantis_enterprisetrack >= 17.1, <= 17.3","managed_file_transfer = 12.2.1.3.0","managed_file_transfer = 12.2.1.4.0","mysql_enterprise_monitor <= 8.0.21","retail_order_broker = 15.0","siebel_apps_-_marketing <= 21.9","siebel_ui_framework <= 20.12","transportation_management = 6.3.7","workload_manager = 12.2.0.1","workload_manager = 18c","workload_manager = 19c","epolicy_orchestrator = 5.9.0","epolicy_orchestrator = 5.9.1","epolicy_orchestrator = 5.10.0"],"patched":["tomcat 9.0.43"],"published":"2020-05-20","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-9484","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","label":"security@apache.org"},{"url":"http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","label":"security@apache.org"},{"url":"http://seclists.org/fulldisclosure/2020/Jun/6","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2021/03/01/2","label":"security@apache.org"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10332","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/","label":"security@apache.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202006-21","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20200528-0005/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4448-1/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4596-1/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2020/Jun/6","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.openwall.com/lists/oss-security/2021/03/01/2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10332","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202006-21","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200528-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4448-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4596-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.56636,"epssPercentile":0.99042,"ingestedAt":"2026-08-25T17:29:29.986Z","exploits":{"github":17,"githubRepos":["https://github.com/threedr3am/tomcat-cluster-session-sync-exp","https://github.com/masahiro331/CVE-2020-9484","https://github.com/seanachao/CVE-2020-9484"],"nuclei":["CVE-2020-9484"],"checkedAt":"2026-09-21T15:24:00.857Z"},"exploitAvailable":true,"slug":"CVE-2020-9484","body":"## Overview\n\nWhen using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter=\"null\" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.\n\n## Affected\n\n- `tomcat >= 7.0.0, < 7.0.108`\n- `tomcat >= 8.5.0, < 8.5.63`\n- `tomcat >= 9.0.1, < 9.0.43`\n- `tomcat = 9.0.0`\n- `tomcat = 10.0.0`\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `leap = 15.1`\n- `fedora = 31`\n- `fedora = 32`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 20.04`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `communications_cloud_native_core_binding_support_function = 1.10.0`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_diameter_signaling_router >= 8.0.0.0, <= 8.4.0.5`\n- `communications_element_manager >= 8.2.0, <= 8.2.2`\n- `communications_instant_messaging_server = 10.0.1.4.0`\n- `communications_session_report_manager >= 8.2.0, <= 8.2.2`\n- `communications_session_route_manager >= 8.2.0, <= 8.2.2`\n- `database = 12.2.0.1`\n- `database = 19c`\n- `database = 21c`\n- `fmw_platform = 12.2.1.3.0`\n- `fmw_platform = 12.2.1.4.0`\n- `hospitality_guest_access = 4.2.0`\n- `hospitality_guest_access = 4.2.1`\n- `instantis_enterprisetrack >= 17.1, <= 17.3`\n- `managed_file_transfer = 12.2.1.3.0`\n- `managed_file_transfer = 12.2.1.4.0`\n- `mysql_enterprise_monitor <= 8.0.21`\n- `retail_order_broker = 15.0`\n- `siebel_apps_-_marketing <= 21.9`\n- `siebel_ui_framework <= 20.12`\n- `transportation_management = 6.3.7`\n- `workload_manager = 12.2.0.1`\n- `workload_manager = 18c`\n- `workload_manager = 19c`\n- `epolicy_orchestrator = 5.9.0`\n- `epolicy_orchestrator = 5.9.1`\n- `epolicy_orchestrator = 5.10.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 9.0.43`","depth":"midnight","depthScore":62,"depthScoreParts":{"impact":38.5,"likelihood":11.3,"exploitation":12,"ransomware":0},"changes":[{"seq":4484,"id":"CVE-2020-9484","ts":1788887183536,"field":"exploit_available","old":"false","new":"true"},{"seq":3367,"id":"CVE-2020-9484","ts":1788886302393,"field":"exploit_available","old":"true","new":"false"},{"seq":2222,"id":"CVE-2020-9484","ts":1788882972073,"field":"exploit_available","old":"false","new":"true"},{"seq":1251,"id":"CVE-2020-9484","ts":1788882383652,"field":"exploit_available","old":"true","new":"false"},{"seq":365,"id":"CVE-2020-9484","ts":1788881819021,"field":"exploit_available","old":"false","new":"true"}]}