The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persist sessions using the FileStore.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsvcUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-api | Sep 28, 2023 | Jan 27, 2022 |
| Amazon_linux | — | Upgrade tomcat8 | Mar 9, 2022 | Jan 27, 2022 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 8.5.75Upgrade Apache Tomcat to 10.0.14Upgrade Apache Tomcat to 9.0.58Upgrade Apache Tomcat to the latest available version | Apr 6, 2022 | Jan 27, 2022 |
| Debian | — | Upgrade tomcat9 | Oct 28, 2022 | Jan 27, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 27, 2022 |
| Suse | — | Upgrade tomcat-el-3_0-apiUpgrade tomcat-libUpgrade tomcat-jsp-2_3-apiUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-jsvcUpgrade tomcat-embedUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-webappsUpgrade tomcat-javadocUpgrade tomcat-admin-webapps | Mar 4, 2022 | Jan 27, 2022 |
| Ubuntu | — | Upgrade tomcat9-docs (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro)Upgrade tomcat8-docs (Ubuntu Pro)Upgrade tomcat9-docsUpgrade tomcat9Upgrade tomcat9 (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade libtomcat9-java | Aug 2, 2024 | Jan 27, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 27, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub