---
id: CVE-2020-9484
title: >-
  When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34,
  8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the
  contents and name of a file on the server; and b) the server is configured to
  use…
summary: >-
  When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34,
  8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the
  contents and name of a file on the server; and b) the server is configured to
  use…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 7.0.0, < 7.0.108'
  - 'tomcat >= 8.5.0, < 8.5.63'
  - 'tomcat >= 9.0.1, < 9.0.43'
  - tomcat = 9.0.0
  - tomcat = 10.0.0
  - debian_linux = 8.0
  - debian_linux = 9.0
  - debian_linux = 10.0
  - leap = 15.1
  - fedora = 31
  - fedora = 32
  - ubuntu_linux = 16.04
  - ubuntu_linux = 20.04
  - agile_engineering_data_management = 6.2.1.0
  - agile_product_lifecycle_management = 9.3.3
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - communications_cloud_native_core_binding_support_function = 1.10.0
  - communications_cloud_native_core_policy = 1.14.0
  - 'communications_diameter_signaling_router >= 8.0.0.0, <= 8.4.0.5'
  - 'communications_element_manager >= 8.2.0, <= 8.2.2'
  - communications_instant_messaging_server = 10.0.1.4.0
  - 'communications_session_report_manager >= 8.2.0, <= 8.2.2'
  - 'communications_session_route_manager >= 8.2.0, <= 8.2.2'
  - database = 12.2.0.1
  - database = 19c
  - database = 21c
  - fmw_platform = 12.2.1.3.0
  - fmw_platform = 12.2.1.4.0
  - hospitality_guest_access = 4.2.0
  - hospitality_guest_access = 4.2.1
  - 'instantis_enterprisetrack >= 17.1, <= 17.3'
  - managed_file_transfer = 12.2.1.3.0
  - managed_file_transfer = 12.2.1.4.0
  - mysql_enterprise_monitor <= 8.0.21
  - retail_order_broker = 15.0
  - siebel_apps_-_marketing <= 21.9
  - siebel_ui_framework <= 20.12
  - transportation_management = 6.3.7
  - workload_manager = 12.2.0.1
  - workload_manager = 18c
  - workload_manager = 19c
  - epolicy_orchestrator = 5.9.0
  - epolicy_orchestrator = 5.9.1
  - epolicy_orchestrator = 5.10.0
patched:
  - tomcat 9.0.43
published: '2020-05-20'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-9484'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html'
    label: security@apache.org
  - url: >-
      http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html
    label: security@apache.org
  - url: 'http://seclists.org/fulldisclosure/2020/Jun/6'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/01/2'
    label: security@apache.org
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10332'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html'
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html'
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html'
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/
    label: security@apache.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/
    label: security@apache.org
  - url: 'https://security.gentoo.org/glsa/202006-21'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20200528-0005/'
    label: security@apache.org
  - url: 'https://usn.ubuntu.com/4448-1/'
    label: security@apache.org
  - url: 'https://usn.ubuntu.com/4596-1/'
    label: security@apache.org
  - url: 'https://www.debian.org/security/2020/dsa-4727'
    label: security@apache.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2020/Jun/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/03/01/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kc.mcafee.com/corporate/index?page=content&id=SB10332'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202006-21'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200528-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4448-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4596-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2020/dsa-4727'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuApr2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2020.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.56636
epssPercentile: 0.99042
ingestedAt: '2026-08-25T17:29:29.986Z'
exploits:
  github: 17
  githubRepos:
    - 'https://github.com/threedr3am/tomcat-cluster-session-sync-exp'
    - 'https://github.com/masahiro331/CVE-2020-9484'
    - 'https://github.com/seanachao/CVE-2020-9484'
  nuclei:
    - CVE-2020-9484
  checkedAt: '2026-09-21T15:24:00.857Z'
exploitAvailable: true
---

## Overview

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

## Affected

- `tomcat >= 7.0.0, < 7.0.108`
- `tomcat >= 8.5.0, < 8.5.63`
- `tomcat >= 9.0.1, < 9.0.43`
- `tomcat = 9.0.0`
- `tomcat = 10.0.0`
- `debian_linux = 8.0`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `leap = 15.1`
- `fedora = 31`
- `fedora = 32`
- `ubuntu_linux = 16.04`
- `ubuntu_linux = 20.04`
- `agile_engineering_data_management = 6.2.1.0`
- `agile_product_lifecycle_management = 9.3.3`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `communications_cloud_native_core_binding_support_function = 1.10.0`
- `communications_cloud_native_core_policy = 1.14.0`
- `communications_diameter_signaling_router >= 8.0.0.0, <= 8.4.0.5`
- `communications_element_manager >= 8.2.0, <= 8.2.2`
- `communications_instant_messaging_server = 10.0.1.4.0`
- `communications_session_report_manager >= 8.2.0, <= 8.2.2`
- `communications_session_route_manager >= 8.2.0, <= 8.2.2`
- `database = 12.2.0.1`
- `database = 19c`
- `database = 21c`
- `fmw_platform = 12.2.1.3.0`
- `fmw_platform = 12.2.1.4.0`
- `hospitality_guest_access = 4.2.0`
- `hospitality_guest_access = 4.2.1`
- `instantis_enterprisetrack >= 17.1, <= 17.3`
- `managed_file_transfer = 12.2.1.3.0`
- `managed_file_transfer = 12.2.1.4.0`
- `mysql_enterprise_monitor <= 8.0.21`
- `retail_order_broker = 15.0`
- `siebel_apps_-_marketing <= 21.9`
- `siebel_ui_framework <= 20.12`
- `transportation_management = 6.3.7`
- `workload_manager = 12.2.0.1`
- `workload_manager = 18c`
- `workload_manager = 19c`
- `epolicy_orchestrator = 5.9.0`
- `epolicy_orchestrator = 5.9.1`
- `epolicy_orchestrator = 5.10.0`

## Remediation

Upgrade past the affected range:

- `tomcat 9.0.43`
