Executive brief
Apache Tomcat contains a path equivalence vulnerability involving internal dots in filenames. When the default servlet has writes enabled and partial PUT is supported, remote attackers can achieve code execution, information disclosure, or file content injection. Remote code execution specifically requires Tomcat's file-based session persistence and a library vulnerable to deserialization.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.2
- Apache Tomcat 10.1.0-M1 through 10.1.34
- Apache Tomcat 9.0.0.M1 through 9.0.98
- Apache Tomcat 8.5.0 through 8.5.100 (EOL)
Timeline
- 2025-03-10: disclosed: Mailing list disclosure
- 2025-04-01: advisory: NVD publication date
- 2025-04-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog