CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2020-13934: tomcat from 8.5.1 (inclusive), through 8.5.56 (inclusive), from 9.0.1 (inclusive), through 9.0.36 (inclusive), 9.0.0 ·…

CVE-2020-13934. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.64124 (percentile 0.99211), scored 2026-10-08.

Affected technology

tomcat · from 8.5.1 (inclusive), through 8.5.56 (inclusive)
apache

tomcat · from 9.0.1 (inclusive), through 9.0.36 (inclusive)
apache

tomcat · 9.0.0 · update milestone10
apache

tomcat · 9.0.0 · update milestone11
apache

tomcat · 9.0.0 · update milestone12
apache

tomcat · 9.0.0 · update milestone13
apache

tomcat · 9.0.0 · update milestone14
apache

tomcat · 9.0.0 · update milestone15
apache

tomcat · 9.0.0 · update milestone16
apache

tomcat · 9.0.0 · update milestone17
apache

tomcat · 9.0.0 · update milestone18
apache

tomcat · 9.0.0 · update milestone19
apache

tomcat · 9.0.0 · update milestone20
apache

tomcat · 9.0.0 · update milestone21
apache

tomcat · 9.0.0 · update milestone22
apache

tomcat · 9.0.0 · update milestone23
apache

tomcat · 9.0.0 · update milestone24
apache

tomcat · 9.0.0 · update milestone25
apache

tomcat · 9.0.0 · update milestone26
apache

tomcat · 9.0.0 · update milestone27
apache

tomcat · 9.0.0 · update milestone5
apache

tomcat · 9.0.0 · update milestone6
apache

tomcat · 9.0.0 · update milestone7
apache

tomcat · 9.0.0 · update milestone8
apache

tomcat · 9.0.0 · update milestone9
apache

tomcat · 10.0.0 · update milestone1
apache

tomcat · 10.0.0 · update milestone2
apache

tomcat · 10.0.0 · update milestone3
apache

tomcat · 10.0.0 · update milestone4
apache

tomcat · 10.0.0 · update milestone5
apache

tomcat · 10.0.0 · update milestone6
apache

debian linux · 9.0
debian

debian linux · 10.0
debian

oncommand system manager · from 3.0.0 (inclusive), through 3.1.3 (inclusive)
netapp

leap · 15.1
opensuse

leap · 15.2
opensuse

ubuntu linux · 20.04
canonical

agile engineering data management · 6.2.1.0
oracle

agile product lifecycle management · 9.3.3
oracle

agile product lifecycle management · 9.3.5
oracle

agile product lifecycle management · 9.3.6
oracle

communications instant messaging server · 10.0.1.5.0
oracle

fmw platform · 12.2.1.3.0
oracle

fmw platform · 12.2.1.4.0
oracle

instantis enterprisetrack · 17.1
oracle

instantis enterprisetrack · 17.2
oracle

instantis enterprisetrack · 17.3
oracle

managed file transfer · 12.2.1.3.0
oracle

managed file transfer · 12.2.1.4.0
oracle

mysql enterprise monitor · through 8.0.21 (inclusive)
oracle

siebel ui framework · through 20.12 (inclusive)
oracle

workload manager · 12.2.0.1
oracle

workload manager · 18c
oracle

workload manager · 19c
oracle

Apache Tomcat · Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36, 8.5.1 to 8.5.56
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-401, CWE-476
CCR priority
46.0 /100 (P3)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
EPSS
0.64124 · percentile 0.99211 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-13934.html