CVE-2025-24813
Last modified
CVE-2025-24813 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.94% chance of exploitation in the next 30 days.
Description
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Tomcat | < 9.0.99 | — |
| Apache | Tomcat | >= 10.1.1, < 10.1.35 | — |
| Apache | Tomcat | >= 11.0.1, < 11.0.3 | — |
| Apache | Tomcat | 10.1.0 | Milestone1 |
| Apache | Tomcat | 11.0.0 | Milestone1 |
| Debian | Debian Linux | 11.0 | — |
| Netapp | Bootstrap Os | All versions | — |
References
- https://www.openwall.com/lists/oss-security/2025/03/10/5Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/04/msg00003.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20250321-0001/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-24813?
How severe is CVE-2025-24813?
How do I fix CVE-2025-24813?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24807eprosima Fast DDS is a C++ implementation of the DDS (Data D…7.1
- CVE-2025-24808Discourse is an open-source discussion platform. Prior to ve…3.1
- CVE-2025-2481The MediaView plugin for WordPress is vulnerable to Reflecte…6.1
- CVE-2025-24810Cross-site scripting vulnerability exists in Simple Image Si…4.8
- CVE-2025-24811A vulnerability has been identified in SIMATIC S7-1200 CPU 1…8.7
- CVE-2025-24812A vulnerability has been identified in SIMATIC S7-1200 CPU 1…7.1
- CVE-2025-24814Core creation allows users to replace "trusted" configset fi…5.5
- CVE-2025-24815Nokia MantaRay NM is subject to an unrestricted file upload …7.8
- CVE-2025-24816Nokia MantaRay is subject to an Improper Access Control vuln…6.5
- CVE-2025-24817Nokia MantaRay NM is vulnerable to an OS command injection v…8
- CVE-2025-24818Nokia MantaRay NM is vulnerable to an OS command injection v…8
- CVE-2025-24819Nokia MantaRay NM is vulnerable to a Relative Path Traversal…5.7
Are you affected by CVE-2025-24813?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
