""ET EXPLOIT Attempted Directory Traversal via HTTP Cookie (CVE-2020-9484)""
SID: 2030256
Revision: 2
Class Type: attempted-recon
Metadata: affected_product Tomcat, attack_target Server, created_at 2020_06_05, cve CVE_2020_9484, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2020_06_05
Reference:
-
cve
-
2020-9484
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HTTP_SERVERS
Destination Port: $HTTP_PORTS
Flow: established,to_server
Contents:
- Value: "|0a|Cookie|3a 20|JSESSIONID=../"
Within:
PCRE: "/^JSESSIONID=..\//C"
Special Options:
- fast_pattern