vendor:
Apache Tomcat
by:
Al Baradi Joy
8.1
CVSS
CRITICAL
Path Equivalence - Remote Code Execution
44, 502
CWE
Product Name: Apache Tomcat
Affected Version From: Apache Tomcat < 11.0.3 / 10.1.35 / 9.0.98
Affected Version To: 11.0.3 / 10.1.35 / 9.0.98
Patch Exists: YES
Related CWE: CVE-2025-24813
CPE: a:apache:tomcat
Platforms Tested: Apache Tomcat 10.1.33
2025
Apache Tomcat Path Equivalence – Remote Code Execution
The exploit allows remote attackers to execute arbitrary code on the target system by uploading a malicious payload to a specific URL and triggering it through a crafted request. This vulnerability is identified as CVE-2025-24813 affecting Apache Tomcat versions prior to 11.0.3, 10.1.35, and 9.0.98.
Mitigation:
To mitigate this vulnerability, it is recommended to update Apache Tomcat to version 11.0.3, 10.1.35, or 9.0.98 or later. Additionally, restrict access to the affected URLs and implement strong input validation.