boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-24813

Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .9993   100.0   YES
AFFECTED
  Product        Versions     Fixed
  Apache Tomcat  11.0.0-M1 –  —
TIMELINE
  Jan 24  Reserved by apache
  Mar 10  Published (CNA: apache)
  Apr 1   Added to CISA KEV, remediation due 2025-04-22
CWE-44, CWE-502 · CNA: apache · CVSS v3.1 · 10 references · KEV due April 22, 2025

Description

Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 24, 2025ReservedReserved by apache
March 10, 2025PublishedPublished (CNA: apache)
April 1, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-04-22

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache Tomcat—11.0.0-M1—

Weaknesses

CWE-44 · CWE-502

References (10)

Related

Authoritative record: CVE-2025-24813 at cve.org

Vendors: apache

Weaknesses: CWE-44 · CWE-502

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-24813 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.