CVE-2025-24813
Description
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
In plain language
AI Act nowCVE-2025-24813 is a serious Apache Tomcat flaw that can let an attacker read sensitive files and possibly upload malicious content—or even run code—if certain settings are enabled; small businesses using affected Tomcat versions should act immediately.
What to do
- Upgrade Apache Tomcat to 11.0.3, 10.1.35, or 9.0.99 (or newer) as soon as possible. 2) If you cannot upgrade immediately, ask your IT person to verify that the default servlet “writes” are not enabled and that partial PUT is not effectively usable. 3) Check whether your Tomcat version falls into the affected ranges and whether any apps store sessions using Tomcat’s file-based session persistence in the default location.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Stop Your Legacy Infrastructure from Hijacking Your AI Agentsen·The Hacker News· Research AWS Bedrock ai-ml
- The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)en·watchTowr Labs· PoC FootPrints web-app
- Киберугрозы 2025-2026: какие уязвимости были и будут в трендеru·Positive Technologies (Хабр)· Roundup rce
- Sipping from the CVE Firehose: How We Prioritize Emerging Threats for Real-World Impacten-us·Bishop Fox· Research
- Tomcat CVE-2025-24813: What You Need to Know Blogen-us·Bishop Fox· PoC Apache Tomcat rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-24813 and every CVE in our database. Create a free account — no credit card required.
Create Free Account