CVE-2025-24813

critical

Description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

References

https://github.com/sivabathina-egen/CVE_Remidiation_tool_test_data

https://github.com/godly-raam/CVE-Research-Portfolio

https://github.com/diedromeo/CVE-Labs-2025-2026

https://github.com/smadonkuan/CVE-LAb

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/sankarayougisrivastewar-sudo/MCATester

https://github.com/Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-

https://github.com/JTMH37/Apache-Tomcat-CVE-2025-24813-Lab

https://github.com/SoWiEee/CVE-Research

https://github.com/suil12/CVE-2025-24813_presentation

https://github.com/ChovTheHacker/EREBUS

https://github.com/Carsonregular365/Exploit-Hub

https://github.com/Enzo-Tssn/PCS3844-CVE_2025_24813

https://github.com/J3ff-R3y/network-scanner-cmdb

https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS

https://github.com/thecosmicexplorer/tools

https://github.com/gregk4sec/cve

https://github.com/seahcy/CVE-2025-24813

https://github.com/gunyakit/CVE-2025-24813-PoC-exploit

https://github.com/Makavellik/POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution

https://github.com/threadpoolx/CVE-2025-24813-Remote-Code-Execution-in-Apache-Tomcat

https://github.com/137f/PoC-CVE-2025-24813

https://github.com/Carvinozheng/CVE-Vulnerability-Analysis

https://github.com/x00byte/PutScanner

https://github.com/abhas9/cve-default-exploitability

https://github.com/Leviticus-Triage/ChromSploit-Framework

https://github.com/mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-

https://github.com/Eduardo-hardvester/CVE-2025-24813

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/wonderl-world1/Tomcat-cve-docker-environment

https://github.com/Erosion2020/CVE-2025-24813-vulhub

https://github.com/heqnx/cve-poc-mon

https://github.com/Mattb709/CVE-2025-24813-Scanner

https://github.com/cchopin/CVE-Arsenal-Lab

https://github.com/f8l124/CVE-2025-24813-POC

https://github.com/horsehacks/CVE-2025-24813-checker

https://github.com/Heimd411/CVE-2025-24813-noPoC

https://github.com/La3B0z/CVE-2025-24813-POC

https://github.com/SkierKing/CVE-Vuln-Analysis

https://github.com/AsaL1n/CVE-2025-24813

https://github.com/AlperenY-cs/CVE-2025-24813

https://github.com/u238/Tomcat-CVE_2025_24813

https://github.com/beyond-devsecops/CVE-2025-24813

https://github.com/msadeghkarimi/CVE-2025-24813-Exploit

https://github.com/imbas007/CVE-2025-24813-apache-tomcat

https://github.com/issamjr/CVE-2025-24813-Scanner

https://github.com/charis3306/CVE-2025-24813

https://github.com/FY036/cve-2025-24813_poc

https://github.com/gregk4sec/CVE-2025-24813

https://github.com/N0c1or/CVE-2025-24813_POC

https://github.com/iSee857/CVE-2025-24813-PoC

https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability

https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability

https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce

https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce

Details

Source: Mitre, NVD

Published: 2025-03-10

Updated: 2025-10-23

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

CVSS v4

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: Critical

EPSS

EPSS: 0.99927

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest