The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsvcUpgrade tomcat-javadocUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-3.1-apiUpgrade tomcat | Sep 28, 2023 | Jan 27, 2022 |
| Amazon_linux | — | Upgrade tomcat8 | Mar 9, 2022 | Jan 27, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.75Upgrade Apache Tomcat to 10.0.14Upgrade Apache Tomcat to 9.0.58 | Apr 6, 2022 | Jan 27, 2022 |
| Debian | — | Upgrade tomcat9 | Oct 28, 2022 | Jan 27, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2022 |
| Suse | — | Upgrade tomcatUpgrade tomcat-jsvcUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-el-3_0-apiUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-javadocUpgrade tomcat-embedUpgrade tomcat-webapps | Mar 4, 2022 | Jan 27, 2022 |
| Ubuntu | — | Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat9Upgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade tomcat8-docs (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat9-docsUpgrade tomcat9-docs (Ubuntu Pro) | Aug 2, 2024 | Jan 27, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub