You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
tomcat-catalina is vulnerable to remote code execution. If a remote attacker knows and is able to control the contents and name of a file, remote code execution can be achieved if the server is configured to use PersistenceManager with a FileStore and the PersistenceManager is configured with the default sessionAttributeValueClassNameFilter="null", through a request that results in the deserialization of the malicious file under the attacker's control. This CVE is due to an incomplete fix for CVE-2020-9484.
Veracode Software Composition Analysis
sessionAttributeValueClassNameFilter="null", through a request that results in the deserialization of the malicious file under the attacker's control. This CVE is due to an incomplete fix for CVE-2020-9484.Links: