CVE-2025-24813

medium KEV
Published 2025-04-07 ยท Modified 2025-04-01
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.0

Description

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

CISA KEV

Vendor
Apache
Product
Tomcat
Due date
2025-04-22

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-52134 webapps multiple
Al Baradi Joy ยท 2025-04-07

Apache Tomcat 11.0.3 - Remote Code Execution

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

Tomcat Partial PUT Java Deserialization
Source fetch failed: fetch_error โ€” view the original via the link above.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 10.1.35-1
sid Fixed 10.1.35-1
forky Fixed 10.1.35-1
bullseye Fixed 9.0.43-2~deb11u12
bookworm Fixed 10.1.34-0+deb12u2
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed โ€”
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat-catalina>=11.0.0-M1,<11.0.311.0.3
java Mavenorg.apache.tomcat:tomcat-catalina>=10.1.0-M1,<10.1.3510.1.35
java Mavenorg.apache.tomcat:tomcat-catalina>=9.0.0.M1,<9.0.999.0.99
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=11.0.0-M1,<11.0.311.0.3
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=10.1.0-M1,<10.1.3510.1.35
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=9.0.0.M1,<9.0.999.0.99
java Mavenorg.apache.tomcat:tomcat-catalina>=8.5.0,<=8.5.100
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=8.5.0,<=8.5.100

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.