Vulnerability Change Records for CVE-2020-1935

Change History

CVE Modified by Apache Software Foundation 7/14/2020 11:15:51 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpujul2020.html [No Types Assigned]

CVE Modified by Apache Software Foundation 7/24/2020 8:15:12 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919@%3Cusers.tomcat.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18@%3Cusers.tomcat.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 3/20/2020 8:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743@%3Ccommits.tomee.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 7/27/2020 7:15:12 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1@%3Cusers.tomcat.apache.org%3E [No Types Assigned]

Reanalysis 3/10/2020 9:43:04 AM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 7.0.0 up to (including) 7.0.99
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (including) 8.5.50
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 9.0.0.m1 up to (including) 9.0.30
OR
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 7.0.0 up to (including) 7.0.99
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (including) 8.5.50
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 9.0.0 up to (including) 9.0.30
     *cpe:2.3:a:apache:tomcat:9.0.0:-:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*
     *cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*

CVE Modified by Apache Software Foundation 3/04/2020 3:15:10 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html [No Types Assigned]

Modified Analysis 2/03/2021 11:43:06 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:* versions up to (including) 20.12
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
Changed Reference Type
https://www.oracle.com/security-alerts/cpujan2021.html No Types Assigned
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
Changed Reference Type
https://www.oracle.com/security-alerts/cpuoct2020.html No Types Assigned
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory

CVE Modified by Apache Software Foundation 10/20/2020 6:15:41 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpuoct2020.html [No Types Assigned]

CVE Modified by Apache Software Foundation 8/10/2020 5:15:12 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://usn.ubuntu.com/4448-1/ [No Types Assigned]

CVE Modified by Apache Software Foundation 7/26/2020 9:15:11 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7@%3Cusers.tomcat.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 7/24/2020 5:15:34 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75@%3Cusers.tomcat.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 5/28/2020 4:15:11 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html [No Types Assigned]

CVE Modified by Apache Software Foundation 5/04/2020 8:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.debian.org/security/2020/dsa-4673 [No Types Assigned]

CVE Modified by Apache Software Foundation 3/15/2020 6:15:14 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html [No Types Assigned]

Modified Analysis 5/04/2021 3:19:13 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
OR
     *cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
     *cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* versions from (including) 3.0.0 up to (including) 3.1.3
Changed CPE Configuration
OR
     *cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:* versions from (including) 17.1 up to (including) 17.3
     *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions up to (including) 4.0.12
     *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions from (including) 4.1 up to (including) 8.0.20
     *cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*
OR
     *cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:* versions from (including) 17.1 up to (including) 17.3
     *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (including) 4.0.12
     *cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* versions from (including) 8.0.0 up to (including) 8.0.20
     *cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:* versions up to (including) 20.5
     *cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*
Removed CPE Configuration
OR
     *cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:* versions up to (including) 20.12

								
						
Removed CPE Configuration
OR
     *cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

								
						
Changed Reference Type
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html Broken Link, Mailing List, Third Party Advisory
Changed Reference Type
https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6@%3Cdev.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6@%3Cdev.tomcat.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://www.oracle.com/security-alerts/cpujul2020.html Patch, Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory

CVE Modified by Apache Software Foundation 1/20/2021 10:15:40 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpujan2021.html [No Types Assigned]

CVE Modified by Apache Software Foundation 3/27/2020 5:15:13 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://security.netapp.com/advisory/ntap-20200327-0005/ [No Types Assigned]

Initial Analysis 3/05/2020 2:7:34 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 7.0.0 up to (including) 7.0.99
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 8.5.0 up to (including) 8.5.50
     *cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* versions from (including) 9.0.0.m1 up to (including) 9.0.30
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:M/Au:N/C:P/I:P/A:N)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Added CWE

								
							
							
						
NIST CWE-444
Changed Reference Type
https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E No Types Assigned
https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E Mailing List, Vendor Advisory
Changed Reference Type
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html No Types Assigned
https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html Third Party Advisory

CVE Modified by Apache Software Foundation 4/28/2021 1:15:08 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6@%3Cdev.tomcat.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 3/23/2020 3:15:14 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78@%3Ccommits.tomee.apache.org%3E [No Types Assigned]

CVE Modified by Apache Software Foundation 5/07/2020 9:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.debian.org/security/2020/dsa-4680 [No Types Assigned]