BlackTreeCVE IntelligenceSAP · 3683579
Linked CVE review
Assess and apply SAP security advisory 3683579
- Linked CVEs
- 2
- Confirmed exploited
- 0
- PoC or lab evidence
- 1
- Maximum CVSS
- 9.6
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2025-55752 PoC or lab evidence Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabledRelative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also e | 7.5 · CVSS 3.1 · HighSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.Public exploit referencedA structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised. | EPSS: 64.4% · 99.2th percentileForecast date: 2026-10-07NETWORK · HIGH complexity · LOW privileges · NONE user interaction | Within 7 daysHigh technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |
CVE-2025-55754 Elevated EPSS forecast Apache Tomcat: console manipulation via escape sequences in log messagesImproper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt | 9.6 · CVSS 3.1 · CriticalSource: CISA ADP | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 10.2% · 95.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 |