The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-javadocUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsvcUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-servlet-3.1-api | Sep 28, 2023 | Jan 27, 2022 |
| Amazon_linux | — | Upgrade tomcat8 | Mar 9, 2022 | Jan 27, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 10.0.14Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.58Upgrade Apache Tomcat to 8.5.75 | Apr 6, 2022 | Jan 27, 2022 |
| Debian | — | Upgrade tomcat9 | Oct 28, 2022 | Jan 27, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2022 |
| Suse | — | Upgrade tomcat-jsp-2_3-apiUpgrade tomcat-libUpgrade tomcat-el-3_0-apiUpgrade tomcat-jsvcUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-javadocUpgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-embed | Mar 4, 2022 | Jan 27, 2022 |
| Ubuntu | — | Upgrade tomcat9Upgrade tomcat8 (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade tomcat9 (Ubuntu Pro)Upgrade tomcat8-docs (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat9-docs (Ubuntu Pro)Upgrade tomcat9-docsUpgrade libtomcat8-java (Ubuntu Pro) | Aug 2, 2024 | Jan 27, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub