CVE-2025-24813
Apache Tomcat: remote code execution via partial PUT on a write-enabled default servlet
Technology
Apache Tomcat
CVSS Score
9.8 / 10.0
Affected Versions
11.0.0-M1 to 11.0.2; 10.1.0-M1 to 10.1.34; 9.0.0.M1 to 9.0.98; end of life but known affected: 8.5.0 to 8.5.100
Upstream Fix
11.0.3; 10.1.35; 9.0.99
Published
March 10, 2025
OSSeva Coverage
Fixed upstream
Description
The partial PUT implementation used a temporary file named from the user-supplied path. Remote code execution requires writes enabled for the default servlet (disabled by default), partial PUT (enabled by default), Tomcat's file-based session persistence in the default location, and a library usable in a deserialization attack. Other conditions allow viewing or injecting content into uploaded files. Fixed in 11.0.3, 10.1.35 and 9.0.99. CISA added it to its Known Exploited Vulnerabilities catalog on 1 April 2025.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.2; 10.1.0-M1 to 10.1.34; 9.0.0.M1 to 9.0.98; end of life but known affected: 8.5.0 to 8.5.100, you need this patch. Book a discovery call to get covered.