When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
CVE-2020-9484
Score elevated to 9.0 because EPSS predicts 93% probability of exploitation within the next 30 days (top 0.2% of all CVEs). NVD baseline CVSS 7.0 retained for reference. Confidence: see factors.
- 186 internet-exposed hosts are running an affected version right now
- High exploitation likelihood — EPSS 57%
A fix is available — apply it.
186 internet-exposed hosts are running an affected version of CVE-2020-9484 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 7.0
- EG Score
- 9.0(high)
- EPSS
- 99.0%
- KEV
- Not listed
Published
May 20, 2020
Last Modified
November 21, 2024
References (84)
- security@apachehttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html
- security@apachehttp://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html
- security@apachehttp://seclists.org/fulldisclosure/2020/Jun/6
- security@apachehttp://www.openwall.com/lists/oss-security/2021/03/01/2
- security@apachehttps://kc.mcafee.com/corporate/index?page=content&id=SB10332
- security@apachehttps://lists.apache.org/thread.html/r11ce01e8a4c7269b88f88212f21830edf73558997ac7744f37769b77%40%3Cusers.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r123b3ebe389f46f9d337923f393cdae4d3e9b78d982d706712f0898c%40%3Ccommits.tomee.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469%40%3Cusers.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r8a2ac0e476dbfc1e6440b09dcc782d444ad635d6da26f0284725a5dc%40%3Cusers.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r8dd19c514face6dd85fd4eab0271854883f40c7307926c1f7cd5400c%40%3Ccommits.tomee.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/raa4123e472175bb052fbba165d37187cea923f755e8f3f30d124cb3f%40%3Ccommits.tomee.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed%40%3Cdev.tomcat.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/rb51ccd58b2152fc75125b2406fc93e04ca9d34e737263faa6ff0f41f%40%3Cusers.tomcat.apache.org%3E
Vendor Advisories for CVE-2020-9484(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(6)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | patch | 2022-07-07 | redhat |
| redhat | tomcat | 2021-08-11 | redhat |
| redhat | tomcat6-0:6.0.24-115.el6_10 | 2020-06-11 | redhat |
| redhat | tomcat-0:7.0.76-12.el7_8 | 2020-06-11 | redhat |
| redhat | tomcat-native-0:1.2.23-22.redhat_22.ep7.el7 | 2020-06-10 | redhat |
| redhat | jws5-tomcat-native-0:1.2.23-5.redhat_5.el8jws | 2020-06-10 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(2 across 1 ecosystem)
Maven(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.99 (70 versions) | 7.0.104 | — |
| org.apache.tomcat:tomcat-catalina | 7.0.0 ... 7.0.99 (70 versions) | 7.0.104 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(8)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHSA-2020:2483IMPORTANT2020-05-20
RHSA-2020:2483 — Important
- Red HatRHSA-2020:2487IMPORTANT2020-05-20
RHSA-2020:2487 — Important
- Red HatRHSA-2020:2506IMPORTANT2020-05-20
RHSA-2020:2506 — Important
- Red HatRHSA-2020:2509IMPORTANT2020-05-20
RHSA-2020:2509 — Important
- Red HatRHSA-2020:2529IMPORTANT2020-05-20
RHSA-2020:2529 — Important
- Red HatRHSA-2020:2530IMPORTANT2020-05-20
RHSA-2020:2530 — Important
- Red HatRHSA-2020:3017IMPORTANT2020-05-20
RHSA-2020:3017 — Important
- Red HatRHSA-2021:3140IMPORTANT2020-05-20
RHSA-2021:3140 — Important
Data Freshness Timeline
(refreshed 7× in last 7d / 33× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:05 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-19 12:00 UTCOSV refresh
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-09 19:07 UTCEPSS rescore
- 2026-07-07 13:43 UTCEPSS rescore
- 2026-07-06 16:25 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-02 16:57 UTCEPSS rescore
- 2026-07-01 21:01 UTCOSV refresh
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
Show 29 moreShow fewer
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-18 17:50 UTCEPSS rescore
- 2026-06-17 17:50 UTCEPSS rescore
- 2026-06-16 17:50 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 02:43 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-27 03:27 UTCEG score recompute
- 2026-05-27 03:27 UTCVendor advisory
- 2026-05-26 13:42 UTCEPSS rescore
- 2026-05-26 13:42 UTCEPSS rescore
Publicly available exploits
(10 references)Working exploit code is in the public domain (10 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC0dayCTF/CVE-2020-9484First seen Sep 16, 2024
Remake of CVE-2020-9484 by Pentestical
Open source ↗ - GitHub PoCd3fudd/CVE-2020-9484_ExploitFirst seen Nov 14, 2022
Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE
Open source ↗ - GitHub PoCRepublicR0K/CVE-2020-9484First seen May 18, 2021
Apache Tomcat RCE (CVE-2020-9484)
Open source ↗ - GitHub PoCVICXOR/CVE-2020-9484First seen Feb 10, 2021
POC for CVE-2020-9484
Open source ↗ - Open source ↗GitHub PoCPenTestical/CVE-2020-9484First seen Dec 31, 2020
- Open source ↗GitHub PoCanjai94/CVE-2020-9484-exploitFirst seen Sep 5, 2020
- GitHub PoCosamahamad/CVE-2020-9484-Mass-ScanFirst seen Jun 5, 2020
CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE
Open source ↗ - GitHub PoCIdealDreamLast/CVE-2020-9484First seen May 21, 2020
用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞
Open source ↗ - Open source ↗GitHub PoCmasahiro331/CVE-2020-9484First seen May 21, 2020
- GitHub PoCthreedr3am/tomcat-cluster-session-sync-expFirst seen May 19, 2020
tomcat使用了自带session同步功能时,不安全的配置(没有使用EncryptInterceptor)导致存在的反序列化漏洞,通过精心构造的数据包, 可以对使用了tomcat自带session同步功能的服务器进行攻击。PS:这个不是CVE-2020-9484,9484是session持久化的洞,这个是session集群同步的洞!
Open source ↗
Frequently asked(5)
What is CVE-2020-9484?
When was CVE-2020-9484 disclosed?
Is CVE-2020-9484 actively exploited?
What is the CVSS score of CVE-2020-9484?
How do I remediate CVE-2020-9484?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-9484
Is Your Infrastructure Affected by CVE-2020-9484?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.