CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2020-9484: tomcat from 7.0.0 (inclusive), before 7.0.108 (exclusive), from 8.5.0 (inclusive), before 8.5.63 (exclusive), from…

CVE-2020-9484. CVSS 3.1 base score 7.0 (HIGH, NVD). EPSS 0.5552 (percentile 0.99016), scored 2026-10-08.

Affected technology

tomcat · from 7.0.0 (inclusive), before 7.0.108 (exclusive)
apache

tomcat · from 8.5.0 (inclusive), before 8.5.63 (exclusive)
apache

tomcat · from 9.0.1 (inclusive), before 9.0.43 (exclusive)
apache

tomcat · 9.0.0 · update milestone1
apache

tomcat · 9.0.0 · update milestone10
apache

tomcat · 9.0.0 · update milestone11
apache

tomcat · 9.0.0 · update milestone12
apache

tomcat · 9.0.0 · update milestone13
apache

tomcat · 9.0.0 · update milestone14
apache

tomcat · 9.0.0 · update milestone15
apache

tomcat · 9.0.0 · update milestone16
apache

tomcat · 9.0.0 · update milestone17
apache

tomcat · 9.0.0 · update milestone18
apache

tomcat · 9.0.0 · update milestone19
apache

tomcat · 9.0.0 · update milestone2
apache

tomcat · 9.0.0 · update milestone20
apache

tomcat · 9.0.0 · update milestone21
apache

tomcat · 9.0.0 · update milestone22
apache

tomcat · 9.0.0 · update milestone23
apache

tomcat · 9.0.0 · update milestone24
apache

tomcat · 9.0.0 · update milestone25
apache

tomcat · 9.0.0 · update milestone26
apache

tomcat · 9.0.0 · update milestone27
apache

tomcat · 9.0.0 · update milestone3
apache

tomcat · 9.0.0 · update milestone4
apache

tomcat · 9.0.0 · update milestone5
apache

tomcat · 9.0.0 · update milestone6
apache

tomcat · 9.0.0 · update milestone7
apache

tomcat · 9.0.0 · update milestone8
apache

tomcat · 9.0.0 · update milestone9
apache

tomcat · 10.0.0 · update milestone1
apache

tomcat · 10.0.0 · update milestone2
apache

tomcat · 10.0.0 · update milestone3
apache

tomcat · 10.0.0 · update milestone4
apache

debian linux · 8.0
debian

debian linux · 9.0
debian

debian linux · 10.0
debian

leap · 15.1
opensuse

fedora · 31
fedoraproject

fedora · 32
fedoraproject

ubuntu linux · 16.04
canonical

ubuntu linux · 20.04
canonical

agile engineering data management · 6.2.1.0
oracle

agile product lifecycle management · 9.3.3
oracle

agile product lifecycle management · 9.3.5
oracle

agile product lifecycle management · 9.3.6
oracle

communications cloud native core binding support function · 1.10.0
oracle

communications cloud native core policy · 1.14.0
oracle

communications diameter signaling router · from 8.0.0.0 (inclusive), through 8.4.0.5 (inclusive)
oracle

communications element manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle

communications instant messaging server · 10.0.1.4.0
oracle

communications session report manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle

communications session route manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle

database · 12.2.0.1
oracle

database · 19c
oracle

database · 21c
oracle

fmw platform · 12.2.1.3.0
oracle

fmw platform · 12.2.1.4.0
oracle

hospitality guest access · 4.2.0
oracle

hospitality guest access · 4.2.1
oracle

instantis enterprisetrack · from 17.1 (inclusive), through 17.3 (inclusive)
oracle

managed file transfer · 12.2.1.3.0
oracle

managed file transfer · 12.2.1.4.0
oracle

mysql enterprise monitor · through 8.0.21 (inclusive)
oracle

retail order broker · 15.0
oracle

siebel apps - marketing · through 21.9 (inclusive)
oracle

siebel ui framework · through 20.12 (inclusive)
oracle

transportation management · 6.3.7
oracle

workload manager · 12.2.0.1
oracle

workload manager · 18c
oracle

workload manager · 19c
oracle

epolicy orchestrator · 5.9.0
mcafee

epolicy orchestrator · 5.9.1
mcafee

epolicy orchestrator · 5.10.0
mcafee

epolicy orchestrator · 5.10.0 · update update_1
mcafee

epolicy orchestrator · 5.10.0 · update update_2
mcafee

epolicy orchestrator · 5.10.0 · update update_3
mcafee

Apache Tomcat · Apache Tomcat 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54, 7.0.0 to 7.0.103
Vendor not specified by the source

Description’s affected range: versions 10.0.0-M1 to 10.0.0-M4

Component: Not specified by the source
File: under

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-502
CCR priority
41.9 /100 (P3)
CVSS 3.1
7.0 /10 · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.5552 · percentile 0.99016 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-9484.html