CVE-2020-9484 is a deserialization-of-untrusted-data vulnerability in Apache Tomcat session persistence using PersistentManager backed by FileStore. A crafted request can cause Tomcat to load and deserialize an attacker-controlled server-side file as persisted session data. If the sessionAttributeValueClassNameFilter is null or sufficiently permissive, deserialization may invoke an available Java gadget chain and execute attacker-controlled code. Affected versions are Tomcat 7.0.0 through 7.0.103, 8.5.0 through 8.5.54, 9.0.0.M1 through 9.0.34, and 10.0.0-M1 through 10.0.0-M4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides an operational exploit for CVE-2020-9484, a deserialization vulnerability in Apache Tomcat that can lead to remote code execution. The repository contains two files: a README.md with usage instructions and affected versions, and exploit.sh, a Bash script that automates the exploitation process. The script generates several serialized payloads using ysoserial, including one that downloads a reverse shell script (payload.sh) from the attacker's web server to the target's /tmp directory, another to set permissions, and a final one to execute the script. The payload.sh script opens a reverse shell to the attacker's specified IP and port. The script also generates a wordlist of possible session storage paths to maximize the chance of successful exploitation. The exploit targets Tomcat servers accessible over the network and requires the attacker to host a web server serving the payload. The main attack vector is network-based, exploiting the Tomcat session deserialization via crafted JSESSIONID cookies and file uploads to /index.jsp. The exploit is operational, providing a working reverse shell if successful.
This repository provides a proof-of-concept (POC) exploit for CVE-2020-9484, a remote code execution vulnerability in Apache Tomcat when using PersistentManager with FileStore and a deserialization gadget in the classpath. The repository includes: - A Python exploit script (exploit.py) that automates the attack: it downloads the ysoserial tool, generates malicious serialized session files, uploads a payload and the session files to the vulnerable server, and triggers deserialization via crafted JSESSIONID cookies to achieve RCE. - A sample vulnerable Tomcat server (Dockerfile, context.xml, Java source code) configured to demonstrate the vulnerability, including the required PersistentManager and FileStore setup, and a file upload endpoint at /upload. - The exploit targets Tomcat versions 10.x < 10.0.0-M5, 9.x < 9.0.35, 8.x < 8.5.55, and 7.x < 7.0.104, and requires the attacker to be able to upload arbitrary files and know the upload directory. - The payload is a shell script that makes an HTTP request to a webhook to demonstrate successful code execution, but can be replaced with any shell command. The repository is well-structured, with clear separation between the exploit code and the vulnerable server implementation. The main exploit capabilities are remote code execution via Java deserialization, leveraging file upload and session manipulation. Key fingerprintable endpoints include the file upload URL, the upload and session storage directories, and the webhook used for RCE verification.
This repository provides a proof-of-concept exploit for CVE-2020-9484, a remote code execution vulnerability in Apache Tomcat due to insecure deserialization of session data. The main exploit is a Bash script (CVE-2020-9484.sh) that automates the attack process. It requires the ysoserial tool to generate a malicious serialized payload using the CommonsCollections2 gadget. The script creates a payload that, when deserialized by the vulnerable Tomcat server, opens a reverse shell to the attacker's machine. The exploit works by uploading the malicious session file to the server via a POST request to /upload.jsp, then manipulating the JSESSIONID cookie to point to the uploaded file, triggering deserialization. The README provides usage instructions and prerequisites. The exploit targets Apache Tomcat servers vulnerable to CVE-2020-9484 and requires network access to the server's HTTP port (default 8080).
This repository contains a Python exploit script (CVE-2020-9484-Modified.py) targeting Apache Tomcat servers vulnerable to CVE-2020-9484 (Java deserialization RCE). The exploit automates the process of generating malicious serialized session files using ysoserial (downloaded from GitHub), uploads them to the target Tomcat server, and executes a reverse shell payload. The script supports both command-line arguments and an interactive mode for user input. The payload is a bash reverse shell, and the exploit requires the attacker to run a Python HTTP server to serve the payload and a Netcat listener to catch the shell. The README provides context that this script was designed for a CTF challenge (CERTain Doom on TryHackMe). The main exploit file is well-structured, with clear separation of payload generation, upload, and execution steps. The attack vector is network-based, exploiting the Tomcat server via HTTP. Several fingerprintable endpoints are present, including the ysoserial download URL, the attacker's HTTP server, the Tomcat upload endpoint, and file paths used on the target server.
This repository is a Java-based exploit targeting Apache Tomcat servers configured with session clustering (SimpleTcpCluster) without the EncryptInterceptor. The exploit leverages insecure deserialization in the Tomcat session sync protocol to achieve remote code execution (RCE) or trigger DNS callbacks for out-of-band (OOB) detection. The main entry point is 'TomcatSessionClusterExploit.java', which constructs a malicious serialized payload (using gadget chains for JDK 7u21, JDK 8u20, or URLDNS) and sends it over a TCP connection to the Tomcat cluster session sync port (default 5000, but configurable). The payloads are based on ysoserial gadget chains and allow arbitrary command execution or DNS lookups. The exploit requires the attacker to have network access to the Tomcat cluster sync endpoint, and the target must be running a vulnerable JDK version. The repository includes supporting classes for payload construction, serialization, and Tomcat cluster protocol emulation. Example usage and configuration details are provided in the README, including sample server.xml snippets and command-line invocation. No detection-only scripts are present; the code is a functional exploit.
This repository provides a proof-of-concept (POC) exploit for Apache Tomcat's deserialization vulnerability (CVE-2020-9484). The repository includes a docker-compose setup to quickly deploy a vulnerable Tomcat 10.0.0-M4 instance with a custom context.xml that configures the session manager to use file-based session storage. The main exploit is performed by sending an HTTP request to the deployed Tomcat server's /index.jsp endpoint, setting the JSESSIONID cookie to a path that performs directory traversal (../../../../../usr/local/tomcat/cfx). This triggers the deserialization flaw, resulting in the creation of a file named 'coldfx' in the Tomcat tmp directory, demonstrating successful exploitation. The repository structure is minimal, containing configuration files (context.xml, docker-compose.yml), a simple JSP page for session interaction, and a README with exploitation instructions. No weaponized or automated exploit code is present; the POC relies on manual HTTP requests using curl.
This repository contains a Bash proof-of-concept exploit for CVE-2020-9484, a remote code execution vulnerability in Apache Tomcat 9.0.27 (and possibly other versions) when configured with PersistenceManager and FileStore. The main script, CVE-2020-9484.sh, automates the exploitation process by generating a Bash reverse shell payload, using ysoserial to create Java deserialization payloads, and uploading them to the target Tomcat server via HTTP requests to /upload.jsp. The exploit requires the attacker to run a Python HTTP server to serve the payload and a netcat listener to catch the reverse shell. The README.md provides detailed usage instructions, prerequisites (notably the need for ysoserial), and troubleshooting tips. The exploit demonstrates the vulnerability but is not weaponized for mass exploitation. The endpoints involved include the target's /upload.jsp, the attacker's HTTP server, and file paths used for payload delivery and execution.
This repository is a proof-of-concept exploit for CVE-2020-9484, a remote code execution vulnerability in Apache Tomcat due to insecure session deserialization. The repository contains a Dockerfile that builds a vulnerable Tomcat 10.0.0-M4 environment, deploying a custom context.xml to enable persistent file-based session storage and a crafted groovy.session file as the malicious payload. The index.jsp file is a simple JSP page that interacts with the session. The exploit is performed by sending an HTTP request to /index.jsp with a manipulated JSESSIONID cookie that points to the malicious session file, causing Tomcat to deserialize attacker-controlled data and execute arbitrary code. The README provides clear instructions for building and running the environment, as well as verifying exploitation by checking for the presence of a file named 'rce' in /tmp. The main attack vector is network-based, targeting the Tomcat HTTP interface. The repository is structured as a self-contained Docker environment for easy testing and demonstration of the vulnerability.
This repository is a proof-of-concept exploit for CVE-2020-9484, a remote code execution vulnerability in Apache Tomcat's session persistence mechanism. The repository contains three files: a LICENSE, a brief README.md describing the affected Tomcat versions, and the main exploit script (main.py). The Python script prompts the user for a target URL, checks for the presence of /index.jsp, and then sends a specially crafted HTTP request with a malicious JSESSIONID cookie designed to exploit a path traversal vulnerability. If the target is vulnerable, the script may display the output of the targeted page or indicate if the server is patched. The exploit demonstrates the vulnerability but does not provide a weaponized payload or post-exploitation features. The main attack vector is network-based, targeting HTTP endpoints on vulnerable Tomcat servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Apache Tomcat session-persistence deserialization flaw that can lead to remote code execution.
An Apache Tomcat session-persistence deserialization vulnerability that can lead to remote code execution.
A previously addressed Apache Tomcat remote-code-execution vulnerability via session persistence, referenced because CVE-2021-25329 corrects an incomplete fix.
A previously addressed Apache Tomcat remote code execution vulnerability via session persistence, referenced because the CVE-2021-25329 fix corrects an incomplete remediation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.