7.3

CVE-2025-46701

Apache Tomcat: Security constraint bypass for CGI scripts

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions 
may also be affected.


Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 9.0.0 < 9.0.105
Apache ≫ Tomcat Version >= 10.1.0 < 10.1.41
Apache ≫ Tomcat Version >= 11.0.0 < 11.0.7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.8% 0.853
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-178 Improper Handling of Case Sensitivity

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

https://lists.apache.org/thread/xhqqk9w5q45srcdqhogdk04lhdscv30j
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2025/05/29/4
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html