ENISA EUVD · EUVD-2025-6498Known-exploited evidence recordedPath Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads
- attacker knowledge of the names of security sensitive files being uploaded
- the security sensitive files also being uploaded via partial PUT
If all of the following were true, a malicious user was able to perform remote code execution:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- application was using Tomcat's file based session persistence with the default storage location
- application included a library that may be leveraged in a deserialization attack
Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
Official EUVD record ↗BSI · German · WID-SEC-2025-1564Oracle Siebel CRM: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Siebel CRM ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0823Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0825Oracle Commerce: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Commerce ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0824Oracle Communications Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0511Apache Tomcat: Schwachstelle ermöglicht Manipulation, Codeausführung und Offenlegung von DatenEin entfernter, authentisierter Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren oder Informationen offenzulegen.
Official advisory ↗BSI · German · WID-SEC-2025-1439Dell Secure Connect Gateway: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin Angreifer kann mehrere Schwachstellen in Dell Secure Connect Gateway ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗Canadian Centre for Cyber Security · English · AL25-002Vulnerability impacting Apache Tomcat (CVE-2025-24813)An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested.
Official advisory ↗Canadian Centre for Cyber Security · English · AV25-127Apache Tomcat security advisory (AV25-127)On March 10, 2025, Apache published a security advisory to address a vulnerability in the following products:
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20250312Security Bulletin 12 Mar 2025The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 12 Mar 2025, published on 12 March 2025. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0395Multiples vulnérabilités dans les produits IBMCVERecord?id=CVE-2024-52316
Référence CVE CVE-2024-52317
https://www.cve.org/CVERecord?id=CVE-2024-52317
Référence CVE CVE-2024-5629
https://www.cve.org/CVERecord?id=CVE-2024-5629
Référence CVE CVE-2024-56337
https://www.cve.org/CVERecord?id=CVE-2024-56337
Référence CVE CVE-2024-6232
https://www.cve.org/CVERecord?id=CVE-2024-6232
Référence CVE CVE-2024-6923
https://www.cve.org/CVERecord?id=CVE-2024-6923
Référence CVE CVE-2024-8088
https://www.cve.org/CVERecord?id=CVE-2024-8088
Référence CVE CVE-2025-12818
https://www.cve.org/CVERecord?id=CVE-2025-12818
Référence CVE CVE-2025-14847
https://www.cve.org/CVERecord?id=CVE-2025-14847
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-31650
https://www.cve.org/CVERecord?id=CVE-2025-31650
Référence CVE CVE-2025-31651
https://www.cve.org/CVERecord?id=CVE-2025-31651
Référence CVE CVE-2025-38129
https://www.cve.org/CVERecord?id=CVE-2025-38129
Référence CVE CVE-2025-38248
https://www.cve.org/CVERecord?id=CVE-2025-38248
Référence CVE CVE-2025-40064
https://www.cve.org/CVERecord?id=CVE-2025-40064
Référence CVE CVE-2025-49124
https://www.cve.org/CVERecord?id=CVE-2025-49124
Référence CVE CVE-2025-50181
https://www.cve.org/CVERecord?id=CVE-2025-50181
Référence CVE CVE-2025-52434
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0281Multiples vulnérabilités dans les produits Splunkord?id=CVE-2025-15467
Référence CVE CVE-2025-15468
https://www.cve.org/CVERecord?id=CVE-2025-15468
Référence CVE CVE-2025-1594
https://www.cve.org/CVERecord?id=CVE-2025-1594
Référence CVE CVE-2025-22868
https://www.cve.org/CVERecord?id=CVE-2025-22868
Référence CVE CVE-2025-22870
https://www.cve.org/CVERecord?id=CVE-2025-22870
Référence CVE CVE-2025-22871
https://www.cve.org/CVERecord?id=CVE-2025-22871
Référence CVE CVE-2025-22872
https://www.cve.org/CVERecord?id=CVE-2025-22872
Référence CVE CVE-2025-22874
https://www.cve.org/CVERecord?id=CVE-2025-22874
Référence CVE CVE-2025-22919
https://www.cve.org/CVERecord?id=CVE-2025-22919
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-2759
https://www.cve.org/CVERecord?id=CVE-2025-2759
Référence CVE CVE-2025-30153
https://www.cve.org/CVERecord?id=CVE-2025-30153
Référence CVE CVE-2025-30204
https://www.cve.org/CVERecord?id=CVE-2025-30204
Référence CVE CVE-2025-30749
https://www.cve.org/CVERecord?id=CVE-2025-30749
Référence CVE CVE-2025-30754
https://www.cve.org/CVERecord?id=CVE-2025-30754
Référence CVE CVE-2025-31651
https://www.cve.org/CVERecord?id=CVE-2025-31651
Référence CVE CVE-2025-32988
https://www.cve.org/CVERecord?id=CVE-2025-32988
Référence CVE CVE-2025-32989
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMwareord?id=CVE-2025-23084
Référence CVE CVE-2025-23085
https://www.cve.org/CVERecord?id=CVE-2025-23085
Référence CVE CVE-2025-2312
https://www.cve.org/CVERecord?id=CVE-2025-2312
Référence CVE CVE-2025-23165
https://www.cve.org/CVERecord?id=CVE-2025-23165
Référence CVE CVE-2025-23166
https://www.cve.org/CVERecord?id=CVE-2025-23166
Référence CVE CVE-2025-23167
https://www.cve.org/CVERecord?id=CVE-2025-23167
Référence CVE CVE-2025-24014
https://www.cve.org/CVERecord?id=CVE-2025-24014
Référence CVE CVE-2025-24293
https://www.cve.org/CVERecord?id=CVE-2025-24293
Référence CVE CVE-2025-24294
https://www.cve.org/CVERecord?id=CVE-2025-24294
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24855
https://www.cve.org/CVERecord?id=CVE-2025-24855
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-24970
https://www.cve.org/CVERecord?id=CVE-2025-24970
Référence CVE CVE-2025-25186
https://www.cve.org/CVERecord?id=CVE-2025-25186
Référence CVE CVE-2025-25193
https://www.cve.org/CVERecord?id=CVE-2025-25193
Référence CVE CVE-2025-25724
https://www.cve.org/CVERecord?id=CVE-2025-25724
Référence CVE CVE-2025-26465
https://www.cve.org/CVERecord?id=CVE-2025-26465
Référence CVE CVE-2025-26603
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0756Multiples vulnérabilités dans les produits VMwareord?id=CVE-2025-23157
Référence CVE CVE-2025-23158
https://www.cve.org/CVERecord?id=CVE-2025-23158
Référence CVE CVE-2025-23159
https://www.cve.org/CVERecord?id=CVE-2025-23159
Référence CVE CVE-2025-23161
https://www.cve.org/CVERecord?id=CVE-2025-23161
Référence CVE CVE-2025-23163
https://www.cve.org/CVERecord?id=CVE-2025-23163
Référence CVE CVE-2025-23165
https://www.cve.org/CVERecord?id=CVE-2025-23165
Référence CVE CVE-2025-23166
https://www.cve.org/CVERecord?id=CVE-2025-23166
Référence CVE CVE-2025-24294
https://www.cve.org/CVERecord?id=CVE-2025-24294
Référence CVE CVE-2025-2476
https://www.cve.org/CVERecord?id=CVE-2025-2476
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24855
https://www.cve.org/CVERecord?id=CVE-2025-24855
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-24970
https://www.cve.org/CVERecord?id=CVE-2025-24970
Référence CVE CVE-2025-25193
https://www.cve.org/CVERecord?id=CVE-2025-25193
Référence CVE CVE-2025-26519
https://www.cve.org/CVERecord?id=CVE-2025-26519
Référence CVE CVE-2025-27113
https://www.cve.org/CVERecord?id=CVE-2025-27113
Référence CVE CVE-2025-27144
https://www.cve.org/CVERecord?id=CVE-2025-27144
Référence CVE CVE-2025-27210
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0541Vulnérabilité dans Centreon MapUne vulnérabilité a été découverte dans Centreon Map. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0401Multiples vulnérabilités dans Juniper Networks Secure Analyticsorg/CVERecord?id=CVE-2024-57807
Référence CVE CVE-2024-57979
https://www.cve.org/CVERecord?id=CVE-2024-57979
Référence CVE CVE-2024-7348
https://www.cve.org/CVERecord?id=CVE-2024-7348
Référence CVE CVE-2024-8508
https://www.cve.org/CVERecord?id=CVE-2024-8508
Référence CVE CVE-2024-9823
https://www.cve.org/CVERecord?id=CVE-2024-9823
Référence CVE CVE-2025-0624
https://www.cve.org/CVERecord?id=CVE-2025-0624
Référence CVE CVE-2025-1094
https://www.cve.org/CVERecord?id=CVE-2025-1094
Référence CVE CVE-2025-1244
https://www.cve.org/CVERecord?id=CVE-2025-1244
Référence CVE CVE-2025-21785
https://www.cve.org/CVERecord?id=CVE-2025-21785
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Gestion détaillée du document
le 14 mai 2025
Version initiale
le 30 mai 2025
Ajouts des identifiants CVE CVE-2017-9047, CVE-2021-37533, CVE-2023-52922, CVE-2024-11218, CVE-2024-50302, CVE-2024-53197, CVE-2024-56171, CVE-2024-57807, CVE-2024-57979, CVE-2025-0624, CVE-2025-21785, CVE-2025-24813, CVE-2025-24928, CVE-2025-27363 et CVE-2025-27516.
Alertes
Avis
Bulletins d’
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0370Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-40695
Référence CVE CVE-2024-50302
https://www.cve.org/CVERecord?id=CVE-2024-50302
Référence CVE CVE-2024-51466
https://www.cve.org/CVERecord?id=CVE-2024-51466
Référence CVE CVE-2024-53197
https://www.cve.org/CVERecord?id=CVE-2024-53197
Référence CVE CVE-2024-56171
https://www.cve.org/CVERecord?id=CVE-2024-56171
Référence CVE CVE-2024-57807
https://www.cve.org/CVERecord?id=CVE-2024-57807
Référence CVE CVE-2024-57979
https://www.cve.org/CVERecord?id=CVE-2024-57979
Référence CVE CVE-2025-0624
https://www.cve.org/CVERecord?id=CVE-2025-0624
Référence CVE CVE-2025-21785
https://www.cve.org/CVERecord?id=CVE-2025-21785
Référence CVE CVE-2025-24813
https://www.cve.org/CVERecord?id=CVE-2025-24813
Référence CVE CVE-2025-24928
https://www.cve.org/CVERecord?id=CVE-2025-24928
Référence CVE CVE-2025-27363
https://www.cve.org/CVERecord?id=CVE-2025-27363
Référence CVE CVE-2025-27516
https://www.cve.org/CVERecord?id=CVE-2025-27516
Gestion détaillée du document
le 02 mai 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
france.fr
info.gouv.fr/risques
Premier Ministre / Secrétariat Général de la Défense et de la Sécurité Nationale / Agence nationale de la
sécurité des sys
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0240Vulnérabilité dans les produits VMwareUne vulnérabilité a été découverte dans les produits VMware. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
La vulnérabilité CVE-2025-24813 , qui affecte Apache Tomcat, l'un des composants de Tanzu Platform for Cloud Foundry, permet une exécution de code arbitraire à distance.
Cependant, VMware indique que celle-ci n'est pas exploitable dans ce contexte car leur produit n'autorise par l'écriture pour la servlet par défaut.
L'éditeur prévient toutefois que si des développeurs ont utilisé le java buildpack versions antérieures à 4.79.0 pour construire des applications, celles-ci pourraient être vulnérables.
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0200Vulnérabilité dans Apache TomcatUne vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Official advisory ↗NBSZ-NKI · Hungarian · cve-2025-24813CVE-2025-24813Kritikus
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-007525エンタープライズサーバEP8000ハードウェア マネジメント コンソール(HWMC)製品における脆弱性(CVE-2025-49796他)についてハードウェア マネジメント コンソール(HWMC)およびHRL3(*1)のHWMCコード(*2)に関するセキュリティ問題を修正しました。 対象製品、および詳細は、次項に記載の対象製品、およびCVEを参照してください。 *1HRL(HA Reset feature for LPAR):系切替機構を搭載した専用HWMC *2HWMCコード:HWMC装置を制御するための専用プログラム
Official advisory ↗JVN iPedia · Japanese · JVNDB-2023-028317Apache Tomcat partial PUT におけるリモートコード実行、情報漏えいや改ざんの脆弱性 (CVE-2025-24813)Apache Tomcat の partial PUT の元の実装では、ユーザーが指定したファイル名とパスを基にパス区切り文字を「.」に置き換えた一時ファイルが使用されています。このため、特定の条件下で、リモートコード実行、セキュリティ上重要なファイルの表示やコンテンツ挿入の可能性があります。(CVE-2025-24813、CWE-44、CWE-502)
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6430美 CISA 발표 주요 Exploit 정보공유(Update. 2025-04-01)Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-6413Apache 제품 보안 업데이트 권고Apache Tomcat에서 발생하는 원격 코드 실행 취약점(CVE-2025-24813) [1][2]
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0124Kwetsbaarheden verholpen in Oracle CommunicationsDe kwetsbaarheden in Oracle Communications producten stellen ongeauthenticeerde aanvallers in staat om ongeautoriseerde toegang te verkrijgen tot gevoelige gegevens en kunnen leiden tot Denial-of-Service (DoS) aanvallen. Specifieke versies van de Cloud Native Core, zoals de Binding Support Function en Network Repository Function, zijn getroffen, met CVSS-scores die variëren van 4.3 tot 9.8, wat wijst op significante risico's voor de beschikbaarheid en vertrouwelijkheid van de systemen.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0123Kwetsbaarheden verholpen in Oracle Database ProductenDe kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om een Denial-of-Service te veroorzaken of om ongeautoriseerde toegang te verkrijgen tot gevoelige gegevens en gegevens te manipuleren. Subcomponenten als de RDBMS Listener, Java VM, en andere componenten zijn specifiek kwetsbaar, met CVSS-scores variërend van 5.3 tot 7.5, wat duidt op een gematigd tot hoog risico.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0089Kwetsbaarheid verholpen in Apache TomcatDe kwetsbaarheid bevindt zich in de manier waarop de server omgaat met HTTP PUT-verzoeken. Door een kwaadaardig PUT-verzoek te sturen, kan een aanvaller willekeurige bestanden uploaden en uiteindelijk remote code execution (RCE) verkrijgen. Dit stelt hen in staat om volledige controle over de server te krijgen Deze kwetsbaarheid wordt momenteel actief misbruikt in aanvallen, wat de urgentie van het aanpakken van dit beveiligingsprobleem in getroffen implementaties onderstreept.
Official advisory ↗