Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-24813

Apache Tomcat: remote code execution via partial PUT on a write-enabled default servlet

Technology

Apache Tomcat

CVSS Score

9.8 / 10.0

Affected Versions

11.0.0-M1 to 11.0.2; 10.1.0-M1 to 10.1.34; 9.0.0.M1 to 9.0.98; end of life but known affected: 8.5.0 to 8.5.100

Upstream Fix

11.0.3; 10.1.35; 9.0.99

Published

March 10, 2025

OSSeva Coverage

Fixed upstream

Description

The partial PUT implementation used a temporary file named from the user-supplied path. Remote code execution requires writes enabled for the default servlet (disabled by default), partial PUT (enabled by default), Tomcat's file-based session persistence in the default location, and a library usable in a deserialization attack. Other conditions allow viewing or injecting content into uploaded files. Fixed in 11.0.3, 10.1.35 and 9.0.99. CISA added it to its Known Exploited Vulnerabilities catalog on 1 April 2025.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.2; 10.1.0-M1 to 10.1.34; 9.0.0.M1 to 9.0.98; end of life but known affected: 8.5.0 to 8.5.100, you need this patch. Book a discovery call to get covered.