PT-2025-43996 · Apache+9 · Apache Tomcat+9

Published

2025-09-08

·

Updated

2026-04-28

·

CVE-2025-55752

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.10 Apache Tomcat versions 10.1.0-M1 through 10.1.44 Apache Tomcat versions 9.0.0.M11 through 9.0.108 Apache Tomcat versions 8.5.6 through 8.5.100
Description A relative path traversal flaw exists in Apache Tomcat due to a regression introduced by the fix for bug 60013, where rewritten URLs were normalized before decoding. This allows attackers to manipulate the request URI and bypass security constraints protecting directories like /WEB-INF/ and /META-INF/. If HTTP PUT requests are enabled, malicious files can be uploaded, potentially leading to remote code execution (RCE). While PUT requests are typically restricted to trusted users, the possibility of RCE exists when both the vulnerability and PUT requests are enabled. The issue could also lead to console ANSI injection. Approximately 6.1 million potentially affected devices have been identified.
API Endpoints: No specific API endpoints are mentioned.
Vulnerable Parameters or Variables: No specific parameters or variables are mentioned.
Recommendations Apache Tomcat versions 11.0.11 or later Apache Tomcat versions 10.1.45 or later Apache Tomcat versions 9.0.109 or later

Exploit

Fix

RCE

DoS

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:23048
ALSA-2025:23049
ALSA-2025:23050
ALSA-2025:23052
ALSA-2025_16880
ALT-PU-2025-13135
ALT-PU-2025-14452
BDU:2025-13742
BIT-TOMCAT-2025-55752
CVE-2025-55752
GHSA-WMWF-9CCG-FFF5
MGASA-2025-0250
OESA-2025-2559
OESA-2025-2560
OESA-2025-2561
OESA-2025-2562
OESA-2025-2563
OESA-2025-2630
OPENSUSE-SU-2025:15716-1
OPENSUSE-SU-2025:15717-1
OPENSUSE-SU-2025:15718-1
OPENSUSE-SU-2025:20106-1
OPENSUSE-SU-2026:20034-1
OPENSUSE-SU-2026:20444-1
RHSA-2025:19809
RHSA-2026:0292
RHSA-2026:0293
RHSA-2026:2724
RHSA-2026:2725
RHSA-2026:2726
RHSA-2026:6569
RHSA-2026:8334
SUSE-SU-2025:21152-1
SUSE-SU-2025:4086-1
SUSE-SU-2025:4103-1
SUSE-SU-2025:4159-1
SUSE-SU-2025:4184-1
SUSE-SU-2025_21152-1
SUSE-SU-2025_4086-1
SUSE-SU-2025_4103-1
SUSE-SU-2025_4159-1
SUSE-SU-2025_4184-1
SUSE-SU-2026:1058-1
SUSE-SU-2026:20084-1
SUSE-SU-2026:20982-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Bitbucket
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse