VDB
BDU%3A2020-03620
BDU%3A2020-03620
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Уязвимость компонента PersistenceManager сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
6.900000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Oracle Corp., Novell Inc., Сообщество свободного программного обеспечения, Apache Software Foundation, Cisco Systems Inc., АО «ИВК», АО "НППКТ", АО «НТЦ ИТ РОСА», АО «Концерн ВНИИНС» | Red Hat Enterprise Linux, Oracle Retail Order Broker, Instantis EnterpriseTrack, Agile Engineering Data Management, OpenSUSE Leap, Jboss Fuse, Jboss Web Server, Debian GNU/Linux, OpenShift Application Runtimes, Tomcat, Hyperion Infrastructure Technology, Siebel UI Framework, Альт 8 СП (запись в едином реестре российских программ №4305), ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), РОСА ХРОМ (запись в едином реестре российских программ №1607), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Jul 31, 2020 CVE Published
- Jul 29, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00057.html url
- http://packetstormsecurity.com/files/157924/Apache-Tomcat-CVE-2020-9484-Proof-Of-Concept.html url
- http://seclists.org/fulldisclosure/2020/Jun/6 url
- https://lists.apache.org/thread.html/r26950738f4b4ca2d256597cf391d52d3450fa665c297ea5ca38f5469@%3Cusers.tomcat.apache.org%3E url
- https://lists.apache.org/thread.html/r77eae567ed829da9012cadb29af17f2df8fa23bf66faf88229857bb1%40%3Cannounce.tomcat.apache.org%3E url
- https://lists.apache.org/thread.html/r7bc247fffcb1d58415215c861d2354bd653c86266230d78a93c71ae2@%3Cdev.tomcat.apache.org%3E url
- https://lists.apache.org/thread.html/rb1c0fb105ce2b93b7ec6fc1b77dd208022621a91c12d1f580813cfed@%3Cdev.tomcat.apache.org%3E url
- https://lists.apache.org/thread.html/rf70f53af27e04869bdac18b1fc14a3ee529e59eb12292c8791a77926@%3Cusers.tomcat.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2020/05/msg00020.html url
- https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html url
- https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIQHXENTLYUNOES4LXVNJ2NCUQQRF5VJ/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJ7XHKWJWDNWXUJH6UB7CLIW4TWOZ26N/ url
- https://security.gentoo.org/glsa/202006-21 url
- https://security.netapp.com/advisory/ntap-20200528-0005/ url
- https://www.debian.org/security/2020/dsa-4727 url
- https://www.oracle.com/security-alerts/cpujul2020.html url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.6/ url
- https://abf.rosalinux.ru/advisories/ROSA-SA-2023-2258 url
…and 4 more