PT-2025-25560 · Apache+10 · Apache Tomcat+10

Greg K

·

Published

2025-01-01

·

Updated

2026-04-28

·

CVE-2025-49125

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.7 Apache Tomcat versions 10.1.0-M1 through 10.1.41 Apache Tomcat versions 9.0.0.M1 through 9.0.105
Description The issue is related to an Authentication Bypass Using an Alternate Path or Channel vulnerability. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. This path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.
Recommendations For Apache Tomcat versions 11.0.0-M1 through 11.0.7, upgrade to version 11.0.8. For Apache Tomcat versions 10.1.0-M1 through 10.1.41, upgrade to version 10.1.42. For Apache Tomcat versions 9.0.0.M1 through 9.0.105, upgrade to version 9.0.106.

Fix

DoS

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:14177
ALSA-2025:14178
ALSA-2025:14181
ALT-PU-2025-13135
BDU:2025-09499
BIT-TOMCAT-2025-49125
CESA-2025_14177
CVE-2025-49125
DLA-4244-1
GHSA-WC4R-XQ3C-5CF3
INFSA-2025_14177
INFSA-2025_14181
MGASA-2025-0191
OESA-2025-1644
OESA-2025-1816
OPENSUSE-SU-2025:15301-1
OPENSUSE-SU-2025:15302-1
OPENSUSE-SU-2025:15303-1
RHSA-2025:11695
RHSA-2025:11741
RHSA-2025:14177
RHSA-2025:14178
RHSA-2025:14179
RHSA-2025:14180
RHSA-2025:14181
RHSA-2025:14182
RHSA-2025:14183
RHSA-2025_14177
RHSA-2025_14181
SUSE-SU-2025:02214-1
SUSE-SU-2025:02261-1
SUSE-SU-2025:02280-1
SUSE-SU-2025:02978-1
SUSE-SU-2025:02979-1
SUSE-SU-2025:03024-1
SUSE-SU-2025_02214-1
SUSE-SU-2025_02261-1
SUSE-SU-2025_02280-1
SUSE-SU-2025_02978-1
SUSE-SU-2025_02979-1
SUSE-SU-2025_03024-1
SUSE-SU-2026:1058-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Bitbucket
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse