CVE-2020-9484High· 7.0▾ MidnightPoC availableWhen using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 11.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
57%
17 GitHub repos · Nuclei ×1
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
tomcat >= 7.0.0, < 7.0.108tomcat >= 8.5.0, < 8.5.63tomcat >= 9.0.1, < 9.0.43tomcat = 9.0.0tomcat = 10.0.0debian_linux = 8.0debian_linux = 9.0debian_linux = 10.0leap = 15.1fedora = 31fedora = 32ubuntu_linux = 16.04ubuntu_linux = 20.04agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.3agile_product_lifecycle_management = 9.3.5agile_product_lifecycle_management = 9.3.6communications_cloud_native_core_binding_support_function = 1.10.0communications_cloud_native_core_policy = 1.14.0communications_diameter_signaling_router >= 8.0.0.0, <= 8.4.0.5communications_element_manager >= 8.2.0, <= 8.2.2communications_instant_messaging_server = 10.0.1.4.0communications_session_report_manager >= 8.2.0, <= 8.2.2communications_session_route_manager >= 8.2.0, <= 8.2.2database = 12.2.0.1database = 19cdatabase = 21cfmw_platform = 12.2.1.3.0fmw_platform = 12.2.1.4.0hospitality_guest_access = 4.2.0hospitality_guest_access = 4.2.1instantis_enterprisetrack >= 17.1, <= 17.3managed_file_transfer = 12.2.1.3.0managed_file_transfer = 12.2.1.4.0mysql_enterprise_monitor <= 8.0.21retail_order_broker = 15.0siebel_apps_-_marketing <= 21.9siebel_ui_framework <= 20.12transportation_management = 6.3.7workload_manager = 12.2.0.1workload_manager = 18cworkload_manager = 19cepolicy_orchestrator = 5.9.0epolicy_orchestrator = 5.9.1epolicy_orchestrator = 5.10.0Upgrade past the affected range:
tomcat 9.0.43Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-13935High· 7.5The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104
CVE-2021-33037Medium· 5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse pr…
CVE-2021-25329High· 7.0The fix for CVE-2020-9484 was incomplete
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2020-36180High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
CVE-2020-36179High· 8.1FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.