The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
2021-03-01T12:15:14.280
2024-11-21T05:54:45.850
Modified
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tomcat | ≤ 7.0.107 | Yes |
Application | apache | tomcat | ≤ 8.5.61 | Yes |
Application | apache | tomcat | ≤ 9.0.41 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | oracle | agile_plm | 9.3.3 | Yes |
Application | oracle | agile_plm | 9.3.6 | Yes |
Application | oracle | communications_cloud_native_core_policy | 1.14.0 | Yes |
Application | oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.6.0 | Yes |
Application | oracle | communications_instant_messaging_server | 10.0.1.5.0 | Yes |
Application | oracle | database | 12.2.0.1 | Yes |
Application | oracle | database | 19c | Yes |
Application | oracle | database | 21c | Yes |
Application | oracle | graph_server_and_client | < 21.3.0 | Yes |
Application | oracle | instantis_enterprisetrack | 17.1 | Yes |
Application | oracle | instantis_enterprisetrack | 17.2 | Yes |
Application | oracle | instantis_enterprisetrack | 17.3 | Yes |
Application | oracle | managed_file_transfer | 12.2.1.3.0 | Yes |
Application | oracle | managed_file_transfer | 12.2.1.4.0 | Yes |
Application | oracle | mysql_enterprise_monitor | ≤ 8.0.23 | Yes |
Application | oracle | siebel_ui_framework | < 21.9 | Yes |
Application | oracle | siebel_ui_framework | 21.9 | Yes |