RHSA-2020:2530HighCVSS 7.0

Red Hat Security Advisory: tomcat security update

Published
June 11, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2020-9484 — tomcat: deserialization flaw in session persistence storage leading to RCE

🎯 Affected products58

  • Red Hat Enterprise Linux Client (v. 7)
  • Red Hat Enterprise Linux Client Optional (v. 7)
  • Red Hat Enterprise Linux ComputeNode (v. 7)
  • Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • Red Hat Enterprise Linux Server (v. 7)
  • Red Hat Enterprise Linux Server Optional (v. 7)
  • Red Hat Enterprise Linux Workstation (v. 7)
  • Red Hat Enterprise Linux Workstation Optional (v. 7)
  • tomcat-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-0:7.0.76-12.el7_8.src as a component of Red Hat Enterprise Linux Client (v. 7)
  • tomcat-0:7.0.76-12.el7_8.src as a component of Red Hat Enterprise Linux ComputeNode (v. 7)
  • tomcat-0:7.0.76-12.el7_8.src as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-0:7.0.76-12.el7_8.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-admin-webapps-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-admin-webapps-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-admin-webapps-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • tomcat-docs-webapp-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • tomcat-docs-webapp-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server (v. 7)
  • tomcat-el-2.2-api-0:7.0.76-12.el7_8.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • +28 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Users may configure the PersistenceManager with an appropriate value for sessionAttributeValueClassNameFilter to ensure that only application provided attributes are serialized and deserialized. For more details about the configuration, refer to the Apache Tomcat 9 Configuration Reference https://tomcat.apache.org/tomcat-9.0-doc/config/manager.html.

🔗 References (4)