<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:18:54.991980+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2020-03620</id>
    <title>bdu:2020-03620</title>
    <updated>2026-10-03T04:18:55.020479+00:00</updated>
    <content>bdu:2020-03620</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2020-03620"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2020-9484</id>
    <title>BIT-tomcat-2020-9484</title>
    <updated>2026-10-03T04:18:55.020520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>When using Apache Tomcat versions 9.0.0 through 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2020-9484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2020-avi-315</id>
    <title>certfr-2020-avi-315 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un
attaquant de provoquer une exécution de code ar…</title>
    <updated>2026-10-03T04:18:55.020558+00:00</updated>
    <content>certfr-2020-avi-315</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2020-avi-315"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-34449</id>
    <title>cnvd-2020-34449</title>
    <updated>2026-10-03T04:18:55.020575+00:00</updated>
    <content>cnvd-2020-34449</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-34449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-39149</id>
    <title>EUVD-2026-39149</title>
    <updated>2026-10-03T04:18:55.020588+00:00</updated>
    <content>EUVD-2026-39149</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-39149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-9484</id>
    <title>fkie_cve-2020-9484</title>
    <updated>2026-10-03T04:18:55.020598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-9484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-344f-f5vg-2jfj</id>
    <title>GHSA-344f-f5vg-2jfj — Potential remote code execution in Apache Tomcat</title>
    <updated>2026-10-03T04:18:55.020625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-344f-f5vg-2jfj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-9484</id>
    <title>gsd-2020-9484</title>
    <updated>2026-10-03T04:18:55.020657+00:00</updated>
    <content>gsd-2020-9484</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-9484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0711-1</id>
    <title>openSUSE-SU-2020:0711-1 — Security update for tomcat</title>
    <updated>2026-10-03T04:18:55.020669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0711-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:2483</id>
    <title>RHSA-2020:2483 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 9 security update</title>
    <updated>2026-10-03T04:18:55.020687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat: deserialization flaw in session persistence storage leading to RCE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:2483"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:1363-1</id>
    <title>SUSE-SU-2020:1363-1 — Security update for tomcat</title>
    <updated>2026-10-03T04:18:55.020701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:1363-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-9484</id>
    <title>UBUNTU-CVE-2020-9484</title>
    <updated>2026-10-03T04:18:55.020714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:18.04:LTS: tomcat9, Ubuntu:Pro:18.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:20.04:LTS: tomcat9</p>
<p>When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-9484"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302</id>
    <title>WID-SEC-W-2022-0302 — Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administrator…</title>
    <updated>2026-10-03T04:18:55.020745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial-of-Service-Zustand zu verursachen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0302"/>
  </entry>
</feed>
