tomcat: deserialization flaw in session persistence storage leading to RCE
Published May 20, 2020
7.0
HIGHCVSS 3.1
EPSS 55.52%
Description
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
Affected products
- Vendor n/a Product Apache Tomcat Defaultn/a
- Version Apache Tomcat 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54, 7.0.0 to 7.0.103StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache Tomcat | n/a |
|
Configuration 1
- ≥ 7.0.0 · < 7.0.108
- ≥ 8.5.0 · < 8.5.63
- ≥ 9.0.1 · < 9.0.43
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 9.0.0
- 10.0.0
- 10.0.0
- 10.0.0
- 10.0.0
Configuration 2
- 8.0
- 9.0
- 10.0
Configuration 4
- 31
- 32
Configuration 5
- 16.04
- 20.04
Configuration 6
- 6.2.1.0
- 9.3.3
- 9.3.5
- 9.3.6
- 1.10.0
- 1.14.0
- ≥ 8.0.0.0 · ≤ 8.4.0.5
- ≥ 8.2.0 · ≤ 8.2.2
- 10.0.1.4.0
- ≥ 8.2.0 · ≤ 8.2.2
- ≥ 8.2.0 · ≤ 8.2.2
- 12.2.0.1
- 19c
- 21c
- 12.2.1.3.0
- 12.2.1.4.0
- 4.2.0
- 4.2.1
- ≥ 17.1 · ≤ 17.3
- 12.2.1.3.0
- 12.2.1.4.0
- ≤ 8.0.21
- 15.0
- ≤ 21.9
- ≤ 20.12
- 6.3.7
- 12.2.0.1
- 18c
- 19c
Configuration 7
- 5.9.0
- 5.9.1
- 5.10.0
- 5.10.0
- 5.10.0
- 5.10.0
No data.
Red Hat Enterprise Linux 6
tomcat6-0:6.0.24-115.el6_10
Fixed · RHSA-2020:2529
Red Hat Enterprise Linux 7
tomcat-0:7.0.76-12.el7_8
Fixed · RHSA-2020:2530
Red Hat Fuse 7.11
n/a
Fixed · RHSA-2022:5532
Red Hat Fuse 7.9
tomcat
Fixed · RHSA-2021:3140
Red Hat JBoss Web Server (JWS) 5.3
tomcat
Fixed · RHSA-2020:2509
Red Hat JBoss Web Server 3 for RHEL 6
tomcat-native-0:1.2.23-22.redhat_22.ep7.el6
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3 for RHEL 6
tomcat7-0:7.0.70-40.ep7.el6
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3 for RHEL 6
tomcat8-0:8.0.36-44.ep7.el6
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3 for RHEL 7
tomcat-native-0:1.2.23-22.redhat_22.ep7.el7
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3 for RHEL 7
tomcat7-0:7.0.70-40.ep7.el7
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3 for RHEL 7
tomcat8-0:8.0.36-44.ep7.el7
Fixed · RHSA-2020:2483
Red Hat JBoss Web Server 3.1
tomcat
Fixed · RHSA-2020:2487
Red Hat JBoss Web Server 5.3 on RHEL 6
jws5-tomcat-0:9.0.30-4.redhat_5.1.el6jws
Fixed · RHSA-2020:2506
Red Hat JBoss Web Server 5.3 on RHEL 6
jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws
Fixed · RHSA-2020:2506
Red Hat JBoss Web Server 5.3 on RHEL 7
jws5-tomcat-0:9.0.30-4.redhat_5.1.el7jws
Fixed · RHSA-2020:2506
Red Hat JBoss Web Server 5.3 on RHEL 7
jws5-tomcat-native-0:1.2.23-5.redhat_5.el7jws
Fixed · RHSA-2020:2506
Red Hat JBoss Web Server 5.3 on RHEL 8
jws5-tomcat-0:9.0.30-4.redhat_5.1.el8jws
Fixed · RHSA-2020:2506
Red Hat JBoss Web Server 5.3 on RHEL 8
jws5-tomcat-native-0:1.2.23-5.redhat_5.el8jws
Fixed · RHSA-2020:2506
Red Hat Runtimes Spring Boot 2.1.15
tomcat
Fixed · RHSA-2020:3017
Red Hat Decision Manager 7
tomcat
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/pki-servlet-engine
Fix deferred
Red Hat JBoss Data Grid 6
jbossweb
Not affected
Red Hat JBoss Data Virtualization 6
jbossweb
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jbossweb
Not affected
Red Hat JBoss Fuse 6
tomcat
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Not affected
Red Hat Process Automation 7
tomcat
Not affected
Red Hat Software Collections
rh-java-common-tomcat
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | tomcat6-0:6.0.24-115.el6_10 | Fixed | RHSA-2020:2529 |
| Red Hat Enterprise Linux 7 | tomcat-0:7.0.76-12.el7_8 | Fixed | RHSA-2020:2530 |
| Red Hat Fuse 7.11 | n/a | Fixed | RHSA-2022:5532 |
| Red Hat Fuse 7.9 | tomcat | Fixed | RHSA-2021:3140 |
| Red Hat JBoss Web Server (JWS) 5.3 | tomcat | Fixed | RHSA-2020:2509 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat-native-0:1.2.23-22.redhat_22.ep7.el6 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat7-0:7.0.70-40.ep7.el6 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3 for RHEL 6 | tomcat8-0:8.0.36-44.ep7.el6 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat-native-0:1.2.23-22.redhat_22.ep7.el7 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat7-0:7.0.70-40.ep7.el7 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3 for RHEL 7 | tomcat8-0:8.0.36-44.ep7.el7 | Fixed | RHSA-2020:2483 |
| Red Hat JBoss Web Server 3.1 | tomcat | Fixed | RHSA-2020:2487 |
| Red Hat JBoss Web Server 5.3 on RHEL 6 | jws5-tomcat-0:9.0.30-4.redhat_5.1.el6jws | Fixed | RHSA-2020:2506 |
| Red Hat JBoss Web Server 5.3 on RHEL 6 | jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws | Fixed | RHSA-2020:2506 |
| Red Hat JBoss Web Server 5.3 on RHEL 7 | jws5-tomcat-0:9.0.30-4.redhat_5.1.el7jws | Fixed | RHSA-2020:2506 |
| Red Hat JBoss Web Server 5.3 on RHEL 7 | jws5-tomcat-native-0:1.2.23-5.redhat_5.el7jws | Fixed | RHSA-2020:2506 |
| Red Hat JBoss Web Server 5.3 on RHEL 8 | jws5-tomcat-0:9.0.30-4.redhat_5.1.el8jws | Fixed | RHSA-2020:2506 |
| Red Hat JBoss Web Server 5.3 on RHEL 8 | jws5-tomcat-native-0:1.2.23-5.redhat_5.el8jws | Fixed | RHSA-2020:2506 |
| Red Hat Runtimes Spring Boot 2.1.15 | tomcat | Fixed | RHSA-2020:3017 |
| Red Hat Decision Manager 7 | tomcat | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Fix deferred | n/a |
| Red Hat JBoss Data Grid 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | jbossweb | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | n/a |
| Red Hat JBoss Fuse 6 | tomcat | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Not affected | n/a |
| Red Hat Process Automation 7 | tomcat | Not affected | n/a |
| Red Hat Software Collections | rh-java-common-tomcat | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
In Red Hat Enterprise Linux 8, Red Hat Certificate System 10 and Identity Management are using the pki-servlet-engine component, which embeds a vulnerable version of Tomcat. However, in these specific contexts, the prerequisites to the vulnerability are not met. The PersistentManager is not set, and a SecurityManager is used. The use of pki-servlet-engine outside of these contexts is not supported. As a result, the vulnerability can not be triggered in supported configurations of these products. A future update may update Tomcat in pki-servlet-engine. Red Hat Satellite do not ship Tomcat and rather use its configuration. The product is not affected because configuration does not make use of PersistanceManager or FileStore. Tomcat updates can be obtain from Red Hat Enterprise Linux (RHEL) RHSA.
Red Hat mitigation
Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (35 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 55.52% (0.55520) | 99.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 56.64% (0.56636) | 98.93th | v5 (v2026.06.15) |
| Mar 17, 2025 | 93.22% (0.93219) | 99.80th | v4 (v2025.03.14) |
| Dec 17, 2024 | 93.19% (0.93186) | 99.29th | v3 (v2023.03.01) |
| Dec 12, 2024 | 91.63% (0.91634) | 99.05th | v3 (v2023.03.01) |
| Mar 24, 2024 | 92.25% (0.92247) | 98.90th | v3 (v2023.03.01) |
| Feb 20, 2024 | 92.77% (0.92769) | 98.94th | v3 (v2023.03.01) |
| Feb 7, 2024 | 90.81% (0.90813) | 98.62th | v3 (v2023.03.01) |
| Feb 5, 2024 | 85.69% (0.85692) | 98.31th | v3 (v2023.03.01) |
| Jan 2, 2024 | 88.75% (0.88750) | 98.45th | v3 (v2023.03.01) |
| Dec 16, 2023 | 87.78% (0.87778) | 98.37th | v3 (v2023.03.01) |
| Nov 8, 2023 | 88.36% (0.88360) | 98.39th | v3 (v2023.03.01) |
| Oct 24, 2023 | 97.04% (0.97044) | 99.67th | v3 (v2023.03.01) |
| Oct 8, 2023 | 96.95% (0.96955) | 99.63th | v3 (v2023.03.01) |
| Sep 22, 2023 | 96.88% (0.96878) | 99.59th | v3 (v2023.03.01) |
| Aug 22, 2023 | 97.12% (0.97119) | 99.68th | v3 (v2023.03.01) |
| Jul 22, 2023 | 96.92% (0.96918) | 99.57th | v3 (v2023.03.01) |
| Jul 15, 2023 | 96.97% (0.96967) | 99.59th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.13% (0.97129) | 99.67th | v3 (v2023.03.01) |
| May 24, 2023 | 97.34% (0.97336) | 99.80th | v3 (v2023.03.01) |
| May 8, 2023 | 97.36% (0.97355) | 99.81th | v3 (v2023.03.01) |
| Mar 16, 2023 | 97.01% (0.97010) | 99.54th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.97% (0.96972) | 99.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 89.96% (0.89957) | 99.84th | v2 (v2022.01.01) |
| Feb 4, 2022 | 89.96% (0.89957) | 99.81th | v2 (v2022.01.01) |
| Feb 3, 2022 | 72.38% (0.72375) | 99.69th | v1 |
| Oct 21, 2021 | 72.38% (0.72375) | 99.85th | v1 |
| Sep 1, 2021 | 71.88% (0.71875) | 99.85th | v1 |
| Jul 21, 2021 | 71.88% (0.71875) | 0.00th | v1 |
| Jul 13, 2021 | 71.36% (0.71356) | 0.00th | v1 |
| Jul 3, 2021 | 70.82% (0.70819) | 0.00th | v1 |
| Jul 2, 2021 | 70.26% (0.70260) | 0.00th | v1 |
| Jun 15, 2021 | 69.08% (0.69078) | 0.00th | v1 |
| May 23, 2021 | 68.45% (0.68451) | 0.00th | v1 |
| Apr 14, 2021 | 67.80% (0.67798) | 0.00th | v1 |
References (83)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://mail-archives.apache.org/mod_mbox/tomcat-announce/202005.mbox/%3Ce3a0a517-bf82-ba62-0af6-24b83ea0e4e2%40apache.org%3E
- http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jun/6 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.0-M5
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.104
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.55
- http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.35
- http://www.openwall.com/lists/oss-security/2021/03/01/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-9484 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1838332 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1171928
- https://github.com/advisories/GHSA-344f-f5vg-2jfj Advisory
- https://github.com/apache/tomcat/commit/3aa8f28db7efb311cdd1b6fe15a9cd3b167a2222.patch
- https://github.com/apache/tomcat/commit/4785433a226a20df6acbea49296e1ce7e23de453
- https://github.com/apache/tomcat/commit/6d66e99ef85da93e4d2c2a536ca51aa3418bfaf4
- https://github.com/apache/tomcat/commit/74b105657ffbd1d1de80455f03446c3bbf30d1f5
- https://github.com/apache/tomcat/commit/93f0cc403a9210d469afc2bd9cf03ab3251c6f35
- https://github.com/apache/tomcat/commit/bb33048e3f9b4f2b70e4da2e6c4e34ca89023b1b
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332 x_refsource_CONFIRMThird Party Advisory
- https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E x_refsource_MISCMailing ListMitigationPatchThird Party Advisory
- https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119@%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926@%3Cusers.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.apache.org%3E
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cannounce.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cdev.tomcat.apache.org%3E
- https://lists.apache.org/thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf@%3Cusers.tomcat.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N
- https://nvd.nist.gov/vuln/detail/CVE-2020-9484
- https://security.gentoo.org/glsa/202006-21 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200528-0005 x_refsource_CONFIRMThird Party Advisory
- https://tomcat.apache.org/security-10.html
- https://tomcat.apache.org/security-7.html
- https://tomcat.apache.org/security-8.html
- https://tomcat.apache.org/security-9.html
- https://usn.ubuntu.com/4448-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4596-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9484
- https://www.debian.org/security/2020/dsa-4727 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.