When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
CVE-2020-9484
Score elevated to 8.0 because EPSS predicts 57% probability of exploitation within the next 30 days (top 1.0% of all CVEs). NVD baseline CVSS 7.0 retained for reference. Confidence: see factors.
- 490 internet-exposed hosts are running an affected version right now
- High exploitation likelihood — EPSS 57%
A fix is available — apply it.
490 internet-exposed hosts are running an affected version of CVE-2020-9484 right now.
EchelonGraph is the only CVE feed that fuses live vulnerability intelligence with its own live internet-exposure radar — so you see not just that a CVE is exploited, but how much of the internet is exposed to it right now.
- CVSS v3
- 7.0
- EG Score
- 8.0(high)
- EG Risk
- 63(Track)EG Risk 63/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity80% × 45%Exploitation57% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 57%
- EPSS %ILE
- 99%
- KEV
- Not listed
Published
May 20, 2020
Last Modified
August 25, 2026
Advisory Details (8)
Auto-updated Aug 25, 2026oss-security - CVE-2021-25329: Apache Tomcat Incomplete fix for CVE-2020-9484
http://www.openwall.com/lists/oss-security/2021/03/01/2Full Disclosure: [CVE-2020-9484] Apache Tomcat RCE via PersistentManager
http://seclists.org/fulldisclosure/2020/Jun/6Locked Out | Packet Storm
http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.htmlVendor Advisories for CVE-2020-9484(10)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2022:5532Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Fuse 7.11.0 release and security update
- RHSA-2021:3140Red Hat Product SecurityMedium
Red Hat Security Advisory: Red Hat Fuse 7.9.0 release and security update
- RHSA-2020:3017Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat support for Spring Boot 2.1.15 security and bug fix update
- RHSA-2020:2530Red Hat Product SecurityHigh
Red Hat Security Advisory: tomcat security update
- RHSA-2020:2529Red Hat Product SecurityHigh
Red Hat Security Advisory: tomcat6 security update
- RHSA-2020:2509Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Web Server 5.3.1 security update
- RHSA-2020:2506Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Web Server 5.3.1 security update
- RHSA-2020:2487Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 9 security update
- +2 more
Patch Availability(11)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | tomcat8-user (8.0.32-1ubuntu1.13) @ xenial | 2026-08-25 | ubuntu |
| ubuntu | tomcat9-examples (9.0.31-1ubuntu0.2) @ focal | 2026-08-25 | ubuntu |
| ubuntu | tomcat8-user (8.0.32-1ubuntu1.13+esm1) @ xenial | 2026-08-25 | ubuntu |
| ubuntu | tomcat7-user (7.0.68-1ubuntu0.4+esm2) @ xenial | 2026-08-25 | ubuntu |
| ubuntu | tomcat9-user (9.0.31-1ubuntu0.1) @ focal | 2026-08-25 | ubuntu |
| redhat | patch | 2022-07-07 | redhat |
| redhat | tomcat | 2021-08-11 | redhat |
| redhat | tomcat-0:7.0.76-12.el7_8 | 2020-06-11 | redhat |
| redhat | tomcat6-0:6.0.24-115.el6_10 | 2020-06-11 | redhat |
| redhat | tomcat-native-0:1.2.23-22.redhat_22.ep7.el7 | 2020-06-10 | redhat |
| redhat | jws5-tomcat-native-0:1.2.23-5.redhat_5.el8jws | 2020-06-10 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(10 across 8 ecosystems)
Debian:8(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat7 | 7.0.56-3 ... 7.0.56-3+really7.0.99-1 (19 versions) | 7.0.56-3+really7.0.100-1+deb8u1 | — |
| tomcat8 | 8.0.14-1 ... 8.0.14-1+deb8u9 (17 versions) | 8.0.14-1+deb8u17 | — |
Maven(2)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | 7.0.0 ... 7.0.99 (70 versions) | 7.0.104 | — |
| org.apache.tomcat:tomcat-catalina | 7.0.0 ... 7.0.99 (70 versions) | 7.0.104 | — |
Debian:10(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat9 | 9.0.16-4 ... 9.0.31-1~deb10u1 (7 versions) | 9.0.31-1~deb10u2 | — |
Debian:11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat9 | — | 9.0.35-1 | — |
Debian:12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat9 | — | 9.0.35-1 | — |
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat9 | — | 9.0.35-1 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat9 | — | 9.0.35-1 | — |
Debian:9(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tomcat8 | 8.5.14-1 ... 8.5.54-0+deb9u1 (38 versions) | 8.5.54-0+deb9u2 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(5)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 5× in last 7d / 21× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-18 19:23 UTCEPSS rescore
- 2026-09-17 19:22 UTCEPSS rescore
- 2026-09-16 14:04 UTCEPSS rescore
- 2026-09-15 03:06 UTCEPSS rescore
- 2026-09-13 15:13 UTCOSV refresh
- 2026-09-12 14:57 UTCEPSS rescore
- 2026-09-08 21:56 UTCEPSS rescore
- 2026-09-06 13:44 UTCEPSS rescore
- 2026-09-05 15:25 UTCEPSS rescore
- 2026-09-04 13:57 UTCEPSS rescore
- 2026-09-04 13:57 UTCEPSS rescore
- 2026-09-02 14:08 UTCEPSS rescore
- 2026-08-30 19:14 UTCEPSS rescore
- 2026-08-30 01:19 UTCEPSS rescore
- 2026-08-28 21:37 UTCEPSS rescore
- 2026-08-27 14:21 UTCEPSS rescore
- 2026-08-26 14:42 UTCEPSS rescore
- 2026-08-25 16:36 UTCEG score recompute
- 2026-08-25 16:36 UTCVendor advisory
- 2026-08-21 23:45 UTCEPSS rescore
- 2026-08-20 21:01 UTCOSV refresh
- 2026-08-19 17:00 UTCEPSS rescore
- 2026-08-18 13:44 UTCEPSS rescore
- 2026-08-17 13:43 UTCEPSS rescore
- 2026-08-17 13:43 UTCEPSS rescore
Show 71 moreShow fewer
- 2026-08-16 02:11 UTCEPSS rescore
- 2026-08-15 01:27 UTCEPSS rescore
- 2026-08-13 21:57 UTCEPSS rescore
- 2026-08-12 13:47 UTCEPSS rescore
- 2026-08-08 16:33 UTCEPSS rescore
- 2026-08-06 13:43 UTCEPSS rescore
- 2026-08-05 13:11 UTCOSV refresh
- 2026-08-04 15:06 UTCEPSS rescore
- 2026-08-04 10:34 UTCEPSS rescore
- 2026-08-01 04:12 UTCEPSS rescore
- 2026-07-30 16:25 UTCEPSS rescore
- 2026-07-30 01:27 UTCEPSS rescore
- 2026-07-26 14:52 UTCEPSS rescore
- 2026-07-25 14:15 UTCEPSS rescore
- 2026-07-24 14:15 UTCEPSS rescore
- 2026-07-23 01:55 UTCEG score recompute▲ 1.00
- 2026-07-22 22:42 UTCEG score recompute▼ 2.00
- 2026-07-22 14:05 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-20 17:04 UTCEPSS rescore
- 2026-07-19 12:00 UTCOSV refresh
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-19 02:26 UTCEPSS rescore
- 2026-07-16 17:00 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 22:27 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-13 06:10 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-12 05:44 UTCEPSS rescore
- 2026-07-09 19:07 UTCEPSS rescore
- 2026-07-07 13:43 UTCEPSS rescore
- 2026-07-06 16:25 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-02 16:57 UTCEPSS rescore
- 2026-07-01 21:01 UTCOSV refresh
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-30 23:20 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-28 04:54 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-21 01:57 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-18 17:50 UTCEPSS rescore
- 2026-06-17 17:50 UTCEPSS rescore
- 2026-06-16 17:50 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 02:43 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-06-05 06:08 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-27 03:27 UTCEG score recompute
- 2026-05-27 03:27 UTCVendor advisory
- 2026-05-26 13:42 UTCEPSS rescore
- 2026-05-26 13:42 UTCEPSS rescore
Publicly available exploits
(10 references)Working exploit code is in the public domain (10 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC0dayCTF/CVE-2020-9484First seen Sep 16, 2024
Remake of CVE-2020-9484 by Pentestical
Open source ↗ - GitHub PoCd3fudd/CVE-2020-9484_ExploitFirst seen Nov 14, 2022
Exploit for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE
Open source ↗ - GitHub PoCColdFusionX/CVE-2020-9484First seen Feb 11, 2022
POC - Apache Tomcat Deserialization Vulnerability (CVE-2020-9484)
Open source ↗ - GitHub PoCRepublicR0K/CVE-2020-9484First seen May 18, 2021
Apache Tomcat RCE (CVE-2020-9484)
Open source ↗ - GitHub PoCVICXOR/CVE-2020-9484First seen Feb 10, 2021
POC for CVE-2020-9484
Open source ↗ - Open source ↗GitHub PoCPenTestical/CVE-2020-9484First seen Dec 31, 2020
- Open source ↗GitHub PoCanjai94/CVE-2020-9484-exploitFirst seen Sep 5, 2020
- GitHub PoCosamahamad/CVE-2020-9484-Mass-ScanFirst seen Jun 5, 2020
CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE
Open source ↗ - Open source ↗GitHub PoCmasahiro331/CVE-2020-9484First seen May 21, 2020
- GitHub PoCIdealDreamLast/CVE-2020-9484First seen May 21, 2020
用Kali 2.0复现Apache Tomcat Session反序列化代码执行漏洞
Open source ↗
Frequently asked(5)
What is CVE-2020-9484?
When was CVE-2020-9484 disclosed?
Is CVE-2020-9484 actively exploited?
What is the CVSS score of CVE-2020-9484?
How do I remediate CVE-2020-9484?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2020-9484
Is Your Infrastructure Affected by CVE-2020-9484?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.