December 2025 Patch Tuesday3683579Normal patch window

SAP · 3683579

Linked CVE review

Assess and apply SAP security advisory 3683579

Linked CVEs
2
Confirmed exploited
0
PoC or lab evidence
1
Maximum CVSS
9.6
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
2 of 2 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2025-55752 PoC or lab evidence
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also e

7.5 · CVSS 3.1 · HighSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.EPSS: 64.4% · 99.2th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
CVE-2025-55754 Elevated EPSS forecast
Apache Tomcat: console manipulation via escape sequences in log messages

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt

9.6 · CVSS 3.1 · CriticalSource: CISA ADPNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 10.2% · 95.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258