Vulnerability in Apache Tomcat allowing remote code execution

Published Information about the vulnerability (CVE-2020-9484) in Apache Tomcat, an open implementation of Java Servlet, JavaServer Pages, Java Expression Language, and Java WebSocket technologies. The issue allows for code execution on the server through the sending of a specially crafted request. The vulnerability has been fixed in Apache Tomcat releases 10.0.0-M5, 9.0.35, 8.5.55, and 7.0.104.

For successful exploitation of the vulnerability, the attacker must have control over the content and name of the file on server (for example, if the application has the ability to upload documents or images). Additionally, an attack is possible only on systems that use PersistenceManager with a FileStore where the sessionAttributeValueClassNameFilter parameter is set to 'null' (by default, if SecurityManager is not applied) or a weak filter that allows object deserialization. The attacker must also know or guess the path to the file they control, relative to the location of the FileStore.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster