Junglewise Threat Intelligence

CVE-2025-24813: Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

CVE-2025-24813 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2025-03-10

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat contains a path equivalence vulnerability involving internal dots in filenames. When the default servlet has writes enabled and partial PUT is supported, remote attackers can achieve code execution, information disclosure, or file content injection. Remote code execution specifically requires Tomcat's file-based session persistence and a library vulnerable to deserialization.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.2
  • Apache Tomcat 10.1.0-M1 through 10.1.34
  • Apache Tomcat 9.0.0.M1 through 9.0.98
  • Apache Tomcat 8.5.0 through 8.5.100 (EOL)

Timeline

  • 2025-03-10: disclosed: Mailing list disclosure
  • 2025-04-01: advisory: NVD publication date
  • 2025-04-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats