Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29554
HistoryMar 03, 2021 - 6:05 a.m.

Remote Code Execution

2021-03-0306:05:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.922 High

EPSS

Percentile

99.0%

tomcat-catalina is vulnerable to remote code execution. If a remote attacker knows and is able to control the contents and name of a file, remote code execution can be achieved if the server is configured to use PersistenceManager with a FileStore and the PersistenceManager is configured with the default sessionAttributeValueClassNameFilter="null", through a request that results in the deserialization of the malicious file under the attacker’s control. This CVE is due to an incomplete fix for CVE-2020-9484.

References