CVE-2025-24813KEV · OVERDUECWE-44CWE-502

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT

Critical · published March 10, 2025

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 10.0. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

503
days past CISA
deadline
CVSS v3.1
10.0
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A sneaky path equivalence flaw in Apache Tomcat could let attackers execute code remotely or access sensitive files, all thanks to a default servlet that might be too trusting! 🔥 Think of it like a restaurant kitchen where the chef can accidentally serve up a confidential recipe if the delivery driver misplaces the order — if no one checks, anyone could gain access to secret ingredients! If exploited, an attacker could not only view sensitive files but also sneak in malicious content or even take over the server entirely. This could lead to absolute chaos, from data breaches to full remote control of your applications. It's a nightmare scenario that no one wants to face!

Put simply

Think of it like a restaurant kitchen where the chef can accidentally serve up a confidential recipe if the delivery driver misplaces the order — if no one checks, anyone could gain access to secret ingredients! This vulnerability arises from a path equivalence issue where, under specific circumstances, the default servlet allows unauthorized access to sensitive files or enables remote code execution via maliciously crafted uploads. This can occur when certain Tomcat features are enabled, creating an open door for attackers.

What to do

If exploited, an attacker could not only view sensitive files but also sneak in malicious content or even take over the server entirely. This could lead to absolute chaos, from data breaches to full remote control of your applications. It's a nightmare scenario that no one wants to face! Upgrade immediately to Tomcat versions 11.0.3, 10.1.35, or 9.0.99 to patch this critical vulnerability. Additionally, ensure that write access for the default servlet is disabled and that partial PUT support is managed carefully to minimize risks. Regular audits of file upload processes are also recommended! You've got this! By following these steps, you’ll reinforce your defenses and keep your applications safe! 🛡️

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99927 · 100.0th percentile
Weaknesses
CWE-44 · Path Equivalence: 'file.name' (Internal Dot); CWE-502 · Deserialization of Untrusted Data
Published
2025-03-10T16:44Z
KEV added
2025-04-01 · due 2025-04-22
EPSS history
Timeline
  • 01 APR 00:00Z
    Added to CISA KEV — remediate by Apr 22
    kev
  • 10 MAR 16:44Z
    Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
    cvelistv5