Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813
https://security.netapp.com/advisory/ntap-20250321-0001/
https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html
https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
https://thehackernews.com/2025/04/critical-flaw-in-apache-parquet-allows.html
https://www.darkreading.com/vulnerabilities-threats/apache-tomcat-rce-vulnerability-exploit
https://github.com/sivabathina-egen/CVE_Remidiation_tool_test_data
https://github.com/godly-raam/CVE-Research-Portfolio
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/smadonkuan/CVE-LAb
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/sankarayougisrivastewar-sudo/MCATester
https://github.com/Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-
https://github.com/JTMH37/Apache-Tomcat-CVE-2025-24813-Lab
https://github.com/SoWiEee/CVE-Research
https://github.com/suil12/CVE-2025-24813_presentation
https://github.com/ChovTheHacker/EREBUS
https://github.com/Carsonregular365/Exploit-Hub
https://github.com/Enzo-Tssn/PCS3844-CVE_2025_24813
https://github.com/J3ff-R3y/network-scanner-cmdb
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/thecosmicexplorer/tools
https://github.com/gregk4sec/cve
https://github.com/seahcy/CVE-2025-24813
https://github.com/gunyakit/CVE-2025-24813-PoC-exploit
https://github.com/Makavellik/POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution
https://github.com/threadpoolx/CVE-2025-24813-Remote-Code-Execution-in-Apache-Tomcat
https://github.com/137f/PoC-CVE-2025-24813
https://github.com/Carvinozheng/CVE-Vulnerability-Analysis
https://github.com/x00byte/PutScanner
https://github.com/abhas9/cve-default-exploitability
https://github.com/Leviticus-Triage/ChromSploit-Framework
https://github.com/Eduardo-hardvester/CVE-2025-24813
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/wonderl-world1/Tomcat-cve-docker-environment
https://github.com/Erosion2020/CVE-2025-24813-vulhub
https://github.com/heqnx/cve-poc-mon
https://github.com/Mattb709/CVE-2025-24813-Scanner
https://github.com/cchopin/CVE-Arsenal-Lab
https://github.com/f8l124/CVE-2025-24813-POC
https://github.com/horsehacks/CVE-2025-24813-checker
https://github.com/Heimd411/CVE-2025-24813-noPoC
https://github.com/La3B0z/CVE-2025-24813-POC
https://github.com/SkierKing/CVE-Vuln-Analysis
https://github.com/AsaL1n/CVE-2025-24813
https://github.com/AlperenY-cs/CVE-2025-24813
https://github.com/u238/Tomcat-CVE_2025_24813
https://github.com/beyond-devsecops/CVE-2025-24813
https://github.com/msadeghkarimi/CVE-2025-24813-Exploit
https://github.com/imbas007/CVE-2025-24813-apache-tomcat
https://github.com/issamjr/CVE-2025-24813-Scanner
https://github.com/charis3306/CVE-2025-24813
https://github.com/FY036/cve-2025-24813_poc
https://github.com/gregk4sec/CVE-2025-24813
https://github.com/N0c1or/CVE-2025-24813_POC
https://github.com/iSee857/CVE-2025-24813-PoC
https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability
https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce
https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce
Published: 2025-03-10
Updated: 2025-10-23
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
Base Score: 9.2
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: Critical
EPSS: 0.99927
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest