Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Published Mar 10, 2025 ·Due Apr 22, 2025
9.2
CRITICALCVSS 4.0
EPSS 99.93%
Description
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT
If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack
Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
Affected products
-
- Version 10.1.0-M1StatusaffectedConstraints<=10.1.34
- Version 11.0.0-M1StatusaffectedConstraints<=11.0.2
- Version 8.5.0StatusaffectedConstraints<=8.5.100
- Version 9.0.0.M1StatusaffectedConstraints<=9.0.98
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | unaffected |
|
Configuration 1
- < 9.0.99
- ≥ 10.1.1 · < 10.1.35
- ≥ 11.0.1 · < 11.0.3
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 10.1.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
- 11.0.0
Configuration 2
- 11.0
Configuration 3
- n/a
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 10
tomcat-1:10.1.36-1.el10_0
Fixed · RHSA-2025:7497
Red Hat Enterprise Linux 10
tomcat9-1:9.0.87-5.el10_0
Fixed · RHSA-2025:7494
Red Hat Enterprise Linux 8
tomcat-1:9.0.87-1.el8_10.3
Fixed · RHSA-2025:3683
Red Hat Enterprise Linux 8.8 Extended Update Support
tomcat-1:9.0.87-1.el8_8.4
Fixed · RHSA-2025:3684
Red Hat Enterprise Linux 9
tomcat-1:9.0.87-2.el9_5.1
Fixed · RHSA-2025:3645
Red Hat Enterprise Linux 9.2 Extended Update Support
tomcat-1:9.0.87-1.el9_2.3
Fixed · RHSA-2025:3646
Red Hat Enterprise Linux 9.4 Extended Update Support
tomcat-1:9.0.87-1.el9_4.3
Fixed · RHSA-2025:3647
Red Hat JBoss Web Server 5
tomcat
Fixed · RHSA-2025:3455
Red Hat JBoss Web Server 5.8 on RHEL 7
jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws
Fixed · RHSA-2025:3454
Red Hat JBoss Web Server 5.8 on RHEL 8
jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws
Fixed · RHSA-2025:3454
Red Hat JBoss Web Server 5.8 on RHEL 9
jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws
Fixed · RHSA-2025:3454
Red Hat JBoss Web Server 6.1 on RHEL 8
jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws
Fixed · RHSA-2025:3608
Red Hat JBoss Web Server 6.1 on RHEL 9
jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws
Fixed · RHSA-2025:3608
Red Hat Enterprise Linux 6
tomcat6
Out of support scope
Red Hat Enterprise Linux 7
tomcat
Not affected
Red Hat Enterprise Linux 8
pki-deps:10.6/pki-servlet-engine
Not affected
Red Hat Enterprise Linux 9
pki-servlet-engine
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | tomcat-1:10.1.36-1.el10_0 | Fixed | RHSA-2025:7497 |
| Red Hat Enterprise Linux 10 | tomcat9-1:9.0.87-5.el10_0 | Fixed | RHSA-2025:7494 |
| Red Hat Enterprise Linux 8 | tomcat-1:9.0.87-1.el8_10.3 | Fixed | RHSA-2025:3683 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | tomcat-1:9.0.87-1.el8_8.4 | Fixed | RHSA-2025:3684 |
| Red Hat Enterprise Linux 9 | tomcat-1:9.0.87-2.el9_5.1 | Fixed | RHSA-2025:3645 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | tomcat-1:9.0.87-1.el9_2.3 | Fixed | RHSA-2025:3646 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | tomcat-1:9.0.87-1.el9_4.3 | Fixed | RHSA-2025:3647 |
| Red Hat JBoss Web Server 5 | tomcat | Fixed | RHSA-2025:3455 |
| Red Hat JBoss Web Server 5.8 on RHEL 7 | jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws | Fixed | RHSA-2025:3454 |
| Red Hat JBoss Web Server 5.8 on RHEL 8 | jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws | Fixed | RHSA-2025:3454 |
| Red Hat JBoss Web Server 5.8 on RHEL 9 | jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws | Fixed | RHSA-2025:3454 |
| Red Hat JBoss Web Server 6.1 on RHEL 8 | jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws | Fixed | RHSA-2025:3608 |
| Red Hat JBoss Web Server 6.1 on RHEL 9 | jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws | Fixed | RHSA-2025:3608 |
| Red Hat Enterprise Linux 6 | tomcat6 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pki-servlet-engine | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability has a Moderate impact (rather than Important) because it requires multiple non-default configurations to be exploitable, significantly limiting its impact in typical deployments. For remote code execution (RCE), exploitation requires both file-based session persistence and a library vulnerable to deserialization, further reducing its likelihood. For information disclosure or file injection, the attack is only possible if writes are enabled for the default servlet, partial PUT requests are supported, and sensitive file uploads occur within a publicly writable directory. The combination of all three of these conditions is uncommon in secure environments. Since most modern Tomcat deployments do not meet all these criteria simultaneously, the overall risk is reduced The Tomcat package as shipped in Red Hat Enterprise Linux 6 and 7 is not affected by this vulnerability because the vulnerable code was introduced in a newer Tomcat version. Red Hat Satellite is not directly impacted by this issue as it does not include the affected Tomcat package. However, Tomcat is consumed by Candlepin, a component of Satellite. Red Hat Satellite users are advised to check the impact state of Red Hat Enterprise Linux as any necessary fixes will be distributed through the platform. Satellite configuration does not contain affected parameters that would make Tomcat vulnerable, therefore, even if a vulnerable Tomcat version is shipped with affected RHEL release alongside Satellite, there is no chance of it being exposed to flaw in Red Hat Satellite.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (20)
- http://www.openwall.com/lists/oss-security/2025/03/10/5 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-24813 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2351129 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-6498 Advisory
- https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md exploit
- https://github.com/advisories/GHSA-83qj-6fr2-vhqg Advisory
- https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c
- https://github.com/apache/tomcat/commit/eb61aade8f8daccaecabf07d428b877975622f72
- https://github.com/apache/tomcat/commit/f6c01d6577cf9a1e06792be47e623d36acc3b5dc
- https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq vendor-advisoryVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-24813
- https://security.netapp.com/advisory/ntap-20250321-0001 Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813 government-resourceThird Party AdvisoryUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2025-24813
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce Issue Tracking
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce Issue Tracking
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability Issue Tracking
- https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability Issue Tracking
Change history (0)
No recorded changes yet.