Apache Tomcat Path Equivalence Vulnerability

cve CVE-2025-24813 4 sources, 4 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Apache Tomcat Path Equivalence Vulnerability Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific ve… the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBAl Baradi Joy
receipt
Source
Exploit-DB
Its words
Al Baradi Joy
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Al Baradi Joy",
  "codes": "CVE-2025-24813",
  "date_added": "2025-04-07",
  "date_published": "2025-04-07",
  "date_updated": "2025-04-07",
  "description": "Apache Tomcat 11.0.3 - Remote Code Execution",
  "file": "exploits/multiple/webapps/52134.txt",
  "id": "52134",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Cvss
cvss
Red Hat8.6
receipt
Source
Red Hat
Its words
8.6
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-24813",
  "CWE": "CWE-41",
  "advisories": [
    "RHSA-2025:3454",
    "RHSA-2025:3684",
    "RHSA-2025:3683",
    "RHSA-2025:3608",
    "RHSA-2025:7494",
    "RHSA-2025:7497",
    "RHSA-2025:3647",
    "RHSA-2025:3646",
    "RHSA-2025:3645",
    "RHSA-2025:3455"
  ],
  "affected_packages": [
    "tomcat",
    "tomcat-1:9.0.87-1.el8_8.4",
    "tomcat-1:10.1.36-1.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws",
    "tomcat-1:9.0.87-1.el8_10.3",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws",
    "tomcat9-1:9.0.87-5.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws",
    "tomcat-1:9.0.87-1.el9_2.3",
    "tomcat-1:9.0.87-2.el9_5.1",
    "tomcat-1:9.0.87-1.el9_4.3"
  ],
  "bugzilla": "2351129",
  "bugzilla_description": "tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT",
  "cvss3_score": "8.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-03-10T16:44:03Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-24813.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-41
receipt
Source
Red Hat
Its words
CWE-41
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-24813",
  "CWE": "CWE-41",
  "advisories": [
    "RHSA-2025:3454",
    "RHSA-2025:3684",
    "RHSA-2025:3683",
    "RHSA-2025:3608",
    "RHSA-2025:7494",
    "RHSA-2025:7497",
    "RHSA-2025:3647",
    "RHSA-2025:3646",
    "RHSA-2025:3645",
    "RHSA-2025:3455"
  ],
  "affected_packages": [
    "tomcat",
    "tomcat-1:9.0.87-1.el8_8.4",
    "tomcat-1:10.1.36-1.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws",
    "tomcat-1:9.0.87-1.el8_10.3",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws",
    "tomcat9-1:9.0.87-5.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws",
    "tomcat-1:9.0.87-1.el9_2.3",
    "tomcat-1:9.0.87-2.el9_5.1",
    "tomcat-1:9.0.87-1.el9_4.3"
  ],
  "bugzilla": "2351129",
  "bugzilla_description": "tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT",
  "cvss3_score": "8.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-03-10T16:44:03Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-24813.json",
  "severity": "moderate"
}
—
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-44, CWE-502
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-44, CWE-502
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2025-04-22
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2025-04-22
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Packages
packages
Red Hattomcat, tomcat-1:9.0.87-1.el8_8.4, tomcat-1:10.1.36-1.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws, tomcat-1:9.0.87-1.el8_10.3, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws, tomcat9-1:9.0.87-5.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws, tomcat-1:9.0.87-1.el9_2.3, tomcat-1:9.0.87-2.el9_5.1, tomcat-1:9.0.87-1.el9_4.3
receipt
Source
Red Hat
Its words
tomcat, tomcat-1:9.0.87-1.el8_8.4, tomcat-1:10.1.36-1.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws, tomcat-1:9.0.87-1.el8_10.3, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws, tomcat9-1:9.0.87-5.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws, tomcat-1:9.0.87-1.el9_2.3, tomcat-1:9.0.87-2.el9_5.1, tomcat-1:9.0.87-1.el9_4.3
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-24813",
  "CWE": "CWE-41",
  "advisories": [
    "RHSA-2025:3454",
    "RHSA-2025:3684",
    "RHSA-2025:3683",
    "RHSA-2025:3608",
    "RHSA-2025:7494",
    "RHSA-2025:7497",
    "RHSA-2025:3647",
    "RHSA-2025:3646",
    "RHSA-2025:3645",
    "RHSA-2025:3455"
  ],
  "affected_packages": [
    "tomcat",
    "tomcat-1:9.0.87-1.el8_8.4",
    "tomcat-1:10.1.36-1.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws",
    "tomcat-1:9.0.87-1.el8_10.3",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws",
    "tomcat9-1:9.0.87-5.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws",
    "tomcat-1:9.0.87-1.el9_2.3",
    "tomcat-1:9.0.87-2.el9_5.1",
    "tomcat-1:9.0.87-1.el9_4.3"
  ],
  "bugzilla": "2351129",
  "bugzilla_description": "tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT",
  "cvss3_score": "8.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-03-10T16:44:03Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-24813.json",
  "severity": "moderate"
}
—
Platform
platform
not compared
Exploit-DBmultiple
receipt
Source
Exploit-DB
Its words
multiple
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Al Baradi Joy",
  "codes": "CVE-2025-24813",
  "date_added": "2025-04-07",
  "date_published": "2025-04-07",
  "date_updated": "2025-04-07",
  "description": "Apache Tomcat 11.0.3 - Remote Code Execution",
  "file": "exploits/multiple/webapps/52134.txt",
  "id": "52134",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesLinux,Unix,Windows
receipt
Source
Metasploit exploit modules
Its words
Linux,Unix,Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "sw0rd1ight",
    "Calum Hutton",
    "h4ck3r-04"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a Java deserialization vulnerability in Apache\n          Tomcat's session restoration functionality that can be exploited with a partial HTTP PUT request to\n          place an attacker controlled deserialization payload in the <tomcat_root_dir>/webapps/ROOT/ directory.\n\n          For the exploit to succeed, writes must be enabled for the default servlet,\n          and org.apache.catalina.session.PersistentManager must be configured to use\n          org.apache.catalina.session.FileStore.\n\n          Verified working on 10.1.16-1",
  "disclosure_date": "2025-03-10",
  "fullname": "exploit/multi/http/tomcat_partial_put_deserialization",
  "is_install_path": true,
  "mod_time": "2026-06-02 10:32:30 +0000",
  "name": "Tomcat Partial PUT Java Deserialization",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/tomcat_partial_put_deserialization.rb",
  "platform": "Linux,Unix,Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/tomcat_partial_put_deserialization",
  "references": [
    "CVE-2025-24813",
    "EDB-52134",
    "URL-https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq",
    "URL-https://nvd.nist.gov/vuln/detail/CVE-2025-24813"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Unix Command",
    "Windows Command"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesTomcat
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Tomcat
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 16:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd",
  "author": [
    "sw0rd1ight",
    "Calum Hutton",
    "h4ck3r-04"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module exploits a Java deserialization vulnerability in Apache\n          Tomcat's session restoration functionality that can be exploited with a partial HTTP PUT request to\n          place an attacker controlled deserialization payload in the <tomcat_root_dir>/webapps/ROOT/ directory.\n\n          For the exploit to succeed, writes must be enabled for the default servlet,\n          and org.apache.catalina.session.PersistentManager must be configured to use\n          org.apache.catalina.session.FileStore.\n\n          Verified working on 10.1.16-1",
  "disclosure_date": "2025-03-10",
  "fullname": "exploit/multi/http/tomcat_partial_put_deserialization",
  "is_install_path": true,
  "mod_time": "2026-06-02 10:32:30 +0000",
  "name": "Tomcat Partial PUT Java Deserialization",
  "needs_cleanup": true,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/multi/http/tomcat_partial_put_deserialization.rb",
  "platform": "Linux,Unix,Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "multi/http/tomcat_partial_put_deserialization",
  "references": [
    "CVE-2025-24813",
    "EDB-52134",
    "URL-https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq",
    "URL-https://nvd.nist.gov/vuln/detail/CVE-2025-24813"
  ],
  "rport": 443,
  "session_types": false,
  "targets": [
    "Unix Command",
    "Windows Command"
  ],
  "type": "exploit"
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-02 12:01 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-24813",
  "CWE": "CWE-41",
  "advisories": [
    "RHSA-2025:3454",
    "RHSA-2025:3684",
    "RHSA-2025:3683",
    "RHSA-2025:3608",
    "RHSA-2025:7494",
    "RHSA-2025:7497",
    "RHSA-2025:3647",
    "RHSA-2025:3646",
    "RHSA-2025:3645",
    "RHSA-2025:3455"
  ],
  "affected_packages": [
    "tomcat",
    "tomcat-1:9.0.87-1.el8_8.4",
    "tomcat-1:10.1.36-1.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws",
    "tomcat-1:9.0.87-1.el8_10.3",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws",
    "jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws",
    "tomcat9-1:9.0.87-5.el10_0",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws",
    "jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws",
    "tomcat-1:9.0.87-1.el9_2.3",
    "tomcat-1:9.0.87-2.el9_5.1",
    "tomcat-1:9.0.87-1.el9_4.3"
  ],
  "bugzilla": "2351129",
  "bugzilla_description": "tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT",
  "cvss3_score": "8.6",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2025-03-10T16:44:03Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-24813.json",
  "severity": "moderate"
}
medium
Type
type
Exploit-DBwebapps
receipt
Source
Exploit-DB
Its words
webapps
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Al Baradi Joy",
  "codes": "CVE-2025-24813",
  "date_added": "2025-04-07",
  "date_published": "2025-04-07",
  "date_updated": "2025-04-07",
  "description": "Apache Tomcat 11.0.3 - Remote Code Execution",
  "file": "exploits/multiple/webapps/52134.txt",
  "id": "52134",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesApache
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Apache
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 17:00 UTC
What the source handed over
{
  "cveID": "CVE-2025-24813",
  "cwes": "CWE-44, CWE-502",
  "dateAdded": "2025-04-01",
  "dueDate": "2025-04-22",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq ; https://nvd.nist.gov/vuln/detail/CVE-2025-24813",
  "product": "Tomcat",
  "requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
  "shortDescription": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
  "vendorProject": "Apache",
  "vulnerabilityName": "Apache Tomcat Path Equivalence Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "Al Baradi Joy",
  "codes": "CVE-2025-24813",
  "date_added": "2025-04-07",
  "date_published": "2025-04-07",
  "date_updated": "2025-04-07",
  "description": "Apache Tomcat 11.0.3 - Remote Code Execution",
  "file": "exploits/multiple/webapps/52134.txt",
  "id": "52134",
  "platform": "multiple",
  "port": "",
  "screenshot_url": "",
  "source_url": "",
  "tags": "",
  "type": "webapps",
  "verified": "0"
}
—

vulnerability

Apache Tomcat Path Equivalence Vulnerability
zetlyn/cve-kev · 2025-04-01
cwes CWE-44, CWE-502 due_date 2025-04-22 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Tomcat vendor_project Apache
tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
zetlyn/cve-redhat · 2025-03-10
cvss 8.6 cwe CWE-41 packages tomcat, tomcat-1:9.0.87-1.el8_8.4, tomcat-1:10.1.36-1.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el9jws, tomcat-1:9.0.87-1.el8_10.3, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws, jws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws, tomcat9-1:9.0.87-5.el10_0, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el7jws, jws5-tomcat-0:9.0.87-8.redhat_00008.1.el8jws, tomcat-1:9.0.87-1.el9_2.3, tomcat-1:9.0.87-2.el9_5.1, tomcat-1:9.0.87-1.el9_4.3 severity moderate source

exploit

Tomcat Partial PUT Java Deserialization
zetlyn/cve-metasploit · 2025-03-10
platform Linux,Unix,Windows rank 600 source
Apache Tomcat 11.0.3 - Remote Code Execution
zetlyn/cve-exploitdb · 2025-04-07
author Al Baradi Joy platform multiple type webapps verified false source