Get real-time updates on Telegram
CVE-2020-9484: tomcat from 7.0.0 (inclusive), before 7.0.108 (exclusive), from 8.5.0 (inclusive), before 8.5.63 (exclusive), from…
CVE-2020-9484. CVSS 3.1 base score 7.0 (HIGH, NVD). EPSS 0.5552 (percentile 0.99016), scored 2026-10-08.
Affected technology
tomcat · from 7.0.0 (inclusive), before 7.0.108 (exclusive)
apache
tomcat · from 8.5.0 (inclusive), before 8.5.63 (exclusive)
apache
tomcat · from 9.0.1 (inclusive), before 9.0.43 (exclusive)
apache
tomcat · 9.0.0 · update milestone1
apache
tomcat · 9.0.0 · update milestone10
apache
tomcat · 9.0.0 · update milestone11
apache
tomcat · 9.0.0 · update milestone12
apache
tomcat · 9.0.0 · update milestone13
apache
tomcat · 9.0.0 · update milestone14
apache
tomcat · 9.0.0 · update milestone15
apache
tomcat · 9.0.0 · update milestone16
apache
tomcat · 9.0.0 · update milestone17
apache
tomcat · 9.0.0 · update milestone18
apache
tomcat · 9.0.0 · update milestone19
apache
tomcat · 9.0.0 · update milestone2
apache
tomcat · 9.0.0 · update milestone20
apache
tomcat · 9.0.0 · update milestone21
apache
tomcat · 9.0.0 · update milestone22
apache
tomcat · 9.0.0 · update milestone23
apache
tomcat · 9.0.0 · update milestone24
apache
tomcat · 9.0.0 · update milestone25
apache
tomcat · 9.0.0 · update milestone26
apache
tomcat · 9.0.0 · update milestone27
apache
tomcat · 9.0.0 · update milestone3
apache
tomcat · 9.0.0 · update milestone4
apache
tomcat · 9.0.0 · update milestone5
apache
tomcat · 9.0.0 · update milestone6
apache
tomcat · 9.0.0 · update milestone7
apache
tomcat · 9.0.0 · update milestone8
apache
tomcat · 9.0.0 · update milestone9
apache
tomcat · 10.0.0 · update milestone1
apache
tomcat · 10.0.0 · update milestone2
apache
tomcat · 10.0.0 · update milestone3
apache
tomcat · 10.0.0 · update milestone4
apache
debian linux · 8.0
debian
debian linux · 9.0
debian
debian linux · 10.0
debian
leap · 15.1
opensuse
fedora · 31
fedoraproject
fedora · 32
fedoraproject
ubuntu linux · 16.04
canonical
ubuntu linux · 20.04
canonical
agile engineering data management · 6.2.1.0
oracle
agile product lifecycle management · 9.3.3
oracle
agile product lifecycle management · 9.3.5
oracle
agile product lifecycle management · 9.3.6
oracle
communications cloud native core binding support function · 1.10.0
oracle
communications cloud native core policy · 1.14.0
oracle
communications diameter signaling router · from 8.0.0.0 (inclusive), through 8.4.0.5 (inclusive)
oracle
communications element manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle
communications instant messaging server · 10.0.1.4.0
oracle
communications session report manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle
communications session route manager · from 8.2.0 (inclusive), through 8.2.2 (inclusive)
oracle
database · 12.2.0.1
oracle
database · 19c
oracle
database · 21c
oracle
fmw platform · 12.2.1.3.0
oracle
fmw platform · 12.2.1.4.0
oracle
hospitality guest access · 4.2.0
oracle
hospitality guest access · 4.2.1
oracle
instantis enterprisetrack · from 17.1 (inclusive), through 17.3 (inclusive)
oracle
managed file transfer · 12.2.1.3.0
oracle
managed file transfer · 12.2.1.4.0
oracle
mysql enterprise monitor · through 8.0.21 (inclusive)
oracle
retail order broker · 15.0
oracle
siebel apps - marketing · through 21.9 (inclusive)
oracle
siebel ui framework · through 20.12 (inclusive)
oracle
transportation management · 6.3.7
oracle
workload manager · 12.2.0.1
oracle
workload manager · 18c
oracle
workload manager · 19c
oracle
epolicy orchestrator · 5.9.0
mcafee
epolicy orchestrator · 5.9.1
mcafee
epolicy orchestrator · 5.10.0
mcafee
epolicy orchestrator · 5.10.0 · update update_1
mcafee
epolicy orchestrator · 5.10.0 · update update_2
mcafee
epolicy orchestrator · 5.10.0 · update update_3
mcafee
Apache Tomcat · Apache Tomcat 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54, 7.0.0 to 7.0.103
Vendor not specified by the source
Description’s affected range: versions 10.0.0-M1 to 10.0.0-M4
Component: Not specified by the source
File: under
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
The source reports that an attacker could run code remotely under the conditions described by the source. NVD’s CVSS 3.1 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-502
- CCR priority
- 41.9 /100 (P3)
- CVSS 3.1
- 7.0 /10 · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.5552 · percentile 0.99016 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-9484.html