Get real-time updates on Telegram
CVE-2020-13934: tomcat from 8.5.1 (inclusive), through 8.5.56 (inclusive), from 9.0.1 (inclusive), through 9.0.36 (inclusive), 9.0.0 ·…
CVE-2020-13934. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.64124 (percentile 0.99211), scored 2026-10-08.
Affected technology
tomcat · from 8.5.1 (inclusive), through 8.5.56 (inclusive)
apache
tomcat · from 9.0.1 (inclusive), through 9.0.36 (inclusive)
apache
tomcat · 9.0.0 · update milestone10
apache
tomcat · 9.0.0 · update milestone11
apache
tomcat · 9.0.0 · update milestone12
apache
tomcat · 9.0.0 · update milestone13
apache
tomcat · 9.0.0 · update milestone14
apache
tomcat · 9.0.0 · update milestone15
apache
tomcat · 9.0.0 · update milestone16
apache
tomcat · 9.0.0 · update milestone17
apache
tomcat · 9.0.0 · update milestone18
apache
tomcat · 9.0.0 · update milestone19
apache
tomcat · 9.0.0 · update milestone20
apache
tomcat · 9.0.0 · update milestone21
apache
tomcat · 9.0.0 · update milestone22
apache
tomcat · 9.0.0 · update milestone23
apache
tomcat · 9.0.0 · update milestone24
apache
tomcat · 9.0.0 · update milestone25
apache
tomcat · 9.0.0 · update milestone26
apache
tomcat · 9.0.0 · update milestone27
apache
tomcat · 9.0.0 · update milestone5
apache
tomcat · 9.0.0 · update milestone6
apache
tomcat · 9.0.0 · update milestone7
apache
tomcat · 9.0.0 · update milestone8
apache
tomcat · 9.0.0 · update milestone9
apache
tomcat · 10.0.0 · update milestone1
apache
tomcat · 10.0.0 · update milestone2
apache
tomcat · 10.0.0 · update milestone3
apache
tomcat · 10.0.0 · update milestone4
apache
tomcat · 10.0.0 · update milestone5
apache
tomcat · 10.0.0 · update milestone6
apache
debian linux · 9.0
debian
debian linux · 10.0
debian
oncommand system manager · from 3.0.0 (inclusive), through 3.1.3 (inclusive)
netapp
leap · 15.1
opensuse
leap · 15.2
opensuse
ubuntu linux · 20.04
canonical
agile engineering data management · 6.2.1.0
oracle
agile product lifecycle management · 9.3.3
oracle
agile product lifecycle management · 9.3.5
oracle
agile product lifecycle management · 9.3.6
oracle
communications instant messaging server · 10.0.1.5.0
oracle
fmw platform · 12.2.1.3.0
oracle
fmw platform · 12.2.1.4.0
oracle
instantis enterprisetrack · 17.1
oracle
instantis enterprisetrack · 17.2
oracle
instantis enterprisetrack · 17.3
oracle
managed file transfer · 12.2.1.3.0
oracle
managed file transfer · 12.2.1.4.0
oracle
mysql enterprise monitor · through 8.0.21 (inclusive)
oracle
siebel ui framework · through 20.12 (inclusive)
oracle
workload manager · 12.2.0.1
oracle
workload manager · 18c
oracle
workload manager · 19c
oracle
Apache Tomcat · Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36, 8.5.1 to 8.5.56
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could disrupt service under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.5/10) rates confidentiality and integrity impact as none; availability impact as high.
- CWE
- CWE-401, CWE-476
- CCR priority
- 46.0 /100 (P3)
- CVSS 3.1
- 7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H · NVD
- EPSS
- 0.64124 · percentile 0.99211 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-13934.html