CVE-2020-9484
Tomcat Session Persistence RCE: stopped at runtime
Waratek RASP’s secure runtime rules stop this class of attack out of the box - no application change, no vendor patch, no downtime.
Published May 20, 2020 · Updated November 21, 2024
The vulnerability
Remote code execution via crafted session file deserialization
When Tomcat is configured to use the PersistenceManager with a FileStore and a lax sessionAttributeValueClassNameFilter, an attacker who can place a crafted file at a known relative path can trigger remote code execution through deserialization of session data.
Running an affected version? We can help.
Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.
How Waratek RASP stops it
Blocked at runtime by Waratek RASP
Waratek RASP applies a secure runtime rule that covers this whole class of attack out of the box - the exploit is stopped inside the JVM before it ever reaches a dangerous sink.
Runtime, not perimeter
Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.
No code changes
Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.
Zero false positives
Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.
| Mod | Rules | Enable |
|---|---|---|
| Tomcat Session Persistence RCE protectionCVE-2020-9484 · Unsafe deserialization | 1 | |
| SQL Injection protectionQuery manipulation | 4 | |
| Path Traversal protectionUnsafe file access | 3 |
Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.
Common questions
Tomcat Session Persistence RCE FAQ
Is Tomcat Session Persistence RCE (CVE-2020-9484) exploitable?
CVE-2020-9484 carries a CVSS 7/10 (HIGH) rating and affects Apache Tomcat 7.0.0 through 7.0.103, 8.5.0 through 8.5.54, 9.0.0.M1 through 9.0.34, and 10.0.0-M1 through 10.0.0-M4. When Tomcat is configured to use the PersistenceManager with a FileStore and a lax sessionAttributeValueClassNameFilter, an attacker who can place a crafted file at a known relative path can trigger remote code execution through deserialization of session data.
How does Waratek mitigate Tomcat Session Persistence RCE (CVE-2020-9484)?
Waratek RASP blocks exploitation of Tomcat Session Persistence RCE (CVE-2020-9484) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.
How quickly was Tomcat Session Persistence RCE (CVE-2020-9484) exploited after disclosure?
Exploit code for CVE-2020-9484 was already circulating publicly on May 19, 2020, before the vulnerability was even formally published in the NVD. Attackers had a head start before most defenders had a CVE record to react to.
Protect your apps in production
Get protected against Tomcat Session Persistence RCE - without code changes or redeploying
Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2020-9484 and attacks like it, and get you covered in production.