S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-9484 Scanner

CVE-2020-9484 scanner - Improper Access Control vulnerability in Apache Tomcat

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-9484
7.0
CVSS

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache Tomcatby n/a
Apache Tomcat 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54, 7.0.0 to 7.0.103
Updated Aug 21, 2026View on NVD →
Detail

Apache Tomcat is an open-source Java-based web application server and servlet container. It is widely used by developers to create dynamic websites and process web requests. The server software provides a platform for deploying and running Java-based web applications on various operating systems. It is known for its versatility, scalability, and support for multiple protocols and frameworks. 
 
CVE-2020-9484 is a vulnerability detected in Apache Tomcat versions 7.0.0 to 7.0.103, 8.5.0 to 8.5.54, 9.0.0.M1 to 9.0.34, and 10.0.0-M1 to 10.0.0-M4. The vulnerability allows an attacker to execute remote code by exploiting the PersistenceManager with a FileStore. In other words, if the attacker can control a file on the server and knows the relative path to the FileStore, they can exploit the vulnerability using a specially crafted request. 
 
Exploiting the CVE-2020-9484 vulnerability can lead to serious consequences as it gives unauthorized access to the server and allows attackers to execute arbitrary code, access sensitive data and tamper with the system. The attacker can gain complete control over the server and use it to further propagate malware or launch more attacks. The vulnerability can have severe consequences for businesses that rely on Apache Tomcat as their web application server, compromising their customers' data and putting their reputation at risk. 

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive and actionable information about security vulnerabilities affecting web applications, servers, and other digital assets. By using the platform, businesses can proactively protect their systems and prevent attacks, saving time and resources in the long term.

 

REFERENCES

Solution Advice

To protect against the vulnerability, the following precautions can be taken: 

  • Upgrade to the latest version of Apache Tomcat that contains the fix 
  • Patch the web application server software immediately 
  • Configure a SecurityManager for the PersistenceManager with a proper filter to prevent unauthorized access 
  • Ensure that the server is running in a secure environment and is not exposed to the public internet 
  • Monitor server logs for any unusual activity or attempts to exploit the vulnerability 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.