PT-2025-24053 · Apache · Apache Server

Fabian Weber

·

Published

2025-06-06

·

Updated

2025-06-09

·

CVE-2025-3322

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Apache Server versions prior to the fixed version
Description An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server. This issue affects the Apache Server, allowing attackers to execute code remotely with high privileges.
Recommendations For Apache Server versions prior to the fixed version, update to the latest version that includes the fix for this issue. As a temporary workaround, consider disabling the use of expression language to prevent remote code execution until a patch is available. Restrict access to the server to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-3322

Affected Products

Apache Server