9.8

CVE-2025-24813

Warnung
Medienbericht
Exploit

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions 
may also be affected.


If all of the following were true, a malicious user was able to view       security sensitive files and/or inject content into those files:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads
- attacker knowledge of the names of security sensitive files being uploaded
- the security sensitive files also being uploaded via partial PUT

If all of the following were true, a malicious user was able to       perform remote code execution:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- application was using Tomcat's file based session persistence with the default storage location
- application included a library that may be leveraged in a deserialization attack

Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version < 9.0.99
Apache ≫ Tomcat Version >= 10.1.1 < 10.1.35
Apache ≫ Tomcat Version >= 11.0.1 < 11.0.3
Apache ≫ Tomcat Version 10.1.0 Update milestone1
Apache ≫ Tomcat Version 10.1.0 Update milestone10
Apache ≫ Tomcat Version 10.1.0 Update milestone11
Apache ≫ Tomcat Version 10.1.0 Update milestone12
Apache ≫ Tomcat Version 10.1.0 Update milestone13
Apache ≫ Tomcat Version 10.1.0 Update milestone14
Apache ≫ Tomcat Version 10.1.0 Update milestone15
Apache ≫ Tomcat Version 10.1.0 Update milestone16
Apache ≫ Tomcat Version 10.1.0 Update milestone17
Apache ≫ Tomcat Version 10.1.0 Update milestone18
Apache ≫ Tomcat Version 10.1.0 Update milestone19
Apache ≫ Tomcat Version 10.1.0 Update milestone2
Apache ≫ Tomcat Version 10.1.0 Update milestone20
Apache ≫ Tomcat Version 10.1.0 Update milestone3
Apache ≫ Tomcat Version 10.1.0 Update milestone4
Apache ≫ Tomcat Version 10.1.0 Update milestone5
Apache ≫ Tomcat Version 10.1.0 Update milestone6
Apache ≫ Tomcat Version 10.1.0 Update milestone7
Apache ≫ Tomcat Version 10.1.0 Update milestone8
Apache ≫ Tomcat Version 10.1.0 Update milestone9
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone12
Apache ≫ Tomcat Version 11.0.0 Update milestone13
Apache ≫ Tomcat Version 11.0.0 Update milestone14
Apache ≫ Tomcat Version 11.0.0 Update milestone15
Apache ≫ Tomcat Version 11.0.0 Update milestone16
Apache ≫ Tomcat Version 11.0.0 Update milestone17
Apache ≫ Tomcat Version 11.0.0 Update milestone18
Apache ≫ Tomcat Version 11.0.0 Update milestone19
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone20
Apache ≫ Tomcat Version 11.0.0 Update milestone21
Apache ≫ Tomcat Version 11.0.0 Update milestone22
Apache ≫ Tomcat Version 11.0.0 Update milestone23
Apache ≫ Tomcat Version 11.0.0 Update milestone24
Apache ≫ Tomcat Version 11.0.0 Update milestone25
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Bootstrap Os Version -
   Netapp ≫ Hci Compute Node Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

01.04.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache Tomcat Path Equivalence Vulnerability

Schwachstelle

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 99.93% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-44 Path Equivalence: 'file.name' (Internal Dot)

The product accepts path input in the form of internal dot ('file.ordir') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CWE-706 Use of Incorrectly-Resolved Name or Reference

The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
22.06.2026 16:38
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/03/10/5
Third Party Advisory
Mailing List
https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md
Exploit
https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce
Issue Tracking
https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce
Issue Tracking
https://security.netapp.com/advisory/ntap-20250321-0001/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html
Third Party Advisory
Mailing List
https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability
Issue Tracking
https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability
Issue Tracking
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813
Third Party Advisory
US Government Resource