Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-9484

66
FAUCET Score

CVE-2020-9484 is a critical deserialization vulnerability affecting Apache Tomcat versions 7.x, 8.5.x, 9.0.x, and 10.0.x. Under specific, multi-condition circumstances, an attacker can achieve remote code execution by manipulating server-controlled files and exploiting the PersistenceManager's FileStore. This vulnerability carries a CVSS score of 7.0 (High) due to its potential for complete compromise of confidentiality, integrity, and availability, though it requires high attack complexity and low privileges. While not listed on the KEV catalog, Nuclei templates exist for detection, and its EPSS score of 0.93238 indicates a high probability of exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.0.0, < 7.0.108CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 8.5.0, < 8.5.63CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 9.0.1, < 9.0.43CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
56.64%
Probability of exploitation in next 30 days
EPSS Percentile
99.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2020-9484 · Jul 3, 2020
This CVE's current EPSS score of 0.5664 is in the 100th percentile among its peer group of 1,516 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (29)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 9.0.35
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 8.5.55
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 7.0.104
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 10.0.0-M5
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-catalinaFixed in: 10.0.0-M5
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.35
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 8.5.55
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 7.0.104
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat8-0:8.0.36-44.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat-native-0:1.2.23-22.redhat_22.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 6Fixed in: jws5-tomcat-0:9.0.30-4.redhat_5.1.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 6Fixed in: jws5-tomcat-native-0:1.2.23-5.redhat_5.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 7Fixed in: jws5-tomcat-0:9.0.30-4.redhat_5.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.23-5.redhat_5.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 8Fixed in: jws5-tomcat-0:9.0.30-4.redhat_5.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.3 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.23-5.redhat_5.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server (JWS) 5.3Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Runtimes Spring Boot 2.1.15Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat7-0:7.0.70-40.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: tomcat6-0:6.0.24-115.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: tomcat-0:7.0.76-12.el7_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.9Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3.1Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat8-0:8.0.36-44.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 6Fixed in: tomcat-native-0:1.2.23-22.redhat_22.ep7.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat7-0:7.0.70-40.ep7.el7
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6/pki-servlet-engine

Vendor Advisories (2)

mavenGHSA-344f-f5vg-2jfjhigh

Potential remote code execution in Apache Tomcat

May 21, 2020
redhatCVE-2020-9484Important

tomcat: deserialization flaw in session persistence storage leading to RCE

May 20, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-05/msg00057.html
Third Party Advisory
packetstormsecurity.com / files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html
Third Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2020/Jun/6
Mailing ListThird Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
lists.apache.org / thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E
Mailing ListMitigationPatchThird Party Advisory
lists.apache.org / thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/rc1778b38e74b5b6142414d57623bd55b023a72361f422836782fca3c%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rc8473b08abdf3c16494ed817bec1717a0ee0c8080315bc27db5f21c3%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/rf59c72572b9fee674a5d5cc6afeca4ffc3918a02c354a81cc50b7119%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/rf6d5d57b114678d8898005faef31e9fd6d7c981fcc4ccfc3bc272fc9%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.apache.org%3E
lists.apache.org / thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cannounce.tomcat.apache.org%3E
lists.apache.org / thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/rfe62fbf9d4c314f166fe8c668e50e5d9dd882a99447f26f0367474bf%40%3Cusers.tomcat.apache.org%3E
lists.debian.org / debian-lts-announce/2020/05/msg00020.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/05/msg00026.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2020/07/msg00010.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N
security.gentoo.org / glsa/202006-21
Third Party Advisory
security.netapp.com / advisory/ntap-20200528-0005
Third Party Advisory
usn.ubuntu.com / 4448-1
Third Party Advisory
usn.ubuntu.com / 4596-1
Third Party Advisory
debian.org / security/2020/dsa-4727
Third Party Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujan2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2020.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
oracle.com / security-alerts/cpuoct2020.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
openwall.com / lists/oss-security/2021/03/01/2
Mailing ListThird Party Advisory