E20-15qk1
CVSS:
4.4 (AV:L/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
9
Year:
2020
Description
An insecure deserialization vulnerability exists in Apache Tomcat. The vulnerability is due to insufficient validation of a cached session file before deserialization. An attacker can exploit this vulnerability by crafting a malicious HTTP request. Successful exploitation results in full control of the target server.