Vulnerability record · CVE-2025-24813 · published 10 March 2025
CVE-2025-24813: Apache Tomcat Default Servlet path equivalence enables RCE and file disclosure
Apache · Tomcat
Apache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Default Servlet when writes are enabled. Under specific configurations this leads to remote code execution via deserialization or to disclosure and injection of security-sensitive files.
Description
Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads - attacker knowledge of the names of security sensitive files being uploaded - the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: - writes enabled for the default servlet (disabled by default) - support for partial PUT (enabled by default) - application was using Tomcat's file based session persistence with the default storage location - application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, KEV-listed with a near-certain EPSS score, and public exploit code make this an urgent remote code execution risk.
What it is
Apache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Default Servlet when writes are enabled. Under specific configurations this leads to remote code execution via deserialization or to disclosure and injection of security-sensitive files.
Impact
An attacker can read security-sensitive files, inject content into them, or achieve remote code execution in the Tomcat process, potentially compromising the host and any data it serves.
Attack surface
Reachable over the network through HTTP requests to the Default Servlet; no authentication or user interaction is required per the CVSS vector, but exploitation depends on non-default configuration such as writes enabled for the Default Servlet.
Exploitation
CISA added it to KEV on 2025-04-01 with a 2025-04-22 remediation due date, EPSS 30-day probability is 0.99927 (99.97th percentile), and a public proof-of-concept is referenced, indicating active exploitation.
What to do
- Upgrade to Apache Tomcat 11.0.3, 10.1.35, or 9.0.99 as directed by the vendor advisory.
- Disable write access for the Default Servlet (readonly=true) where it is not required.
- Disable partial PUT support if it is not needed by the application.
- Move file-based session persistence away from the default storage location or avoid it where possible.
- Remove unnecessary deserialization-capable libraries from the classpath.
Detection
- Monitor for HTTP PUT requests with partial content (Content-Range) targeting the Default Servlet or unusual paths containing internal dots.
- Alert on unexpected file creation or modification in Tomcat web application, upload, and session persistence directories.
- Watch for deserialization activity or anomalous child processes spawned by the Tomcat JVM.
- Audit Tomcat configuration for enabled Default Servlet writes and partial PUT support.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24813 to the Known Exploited Vulnerabilities catalog on 1 April 2025 as "Apache Tomcat Path Equivalence Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 April 2025.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/03/10/5 | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html | Mailing ListThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20250321-0001/ | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-24813-detect-apache-tomcat-rce | Issue Tracking |
| https://www.vicarius.io/vsociety/posts/cve-2025-24813-mitigate-apache-tomcat-rce | Issue Tracking |
| https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-detect-vulnerability | Issue Tracking |
| https://www.vicarius.io/vsociety/posts/cve-2025-24813-tomcat-mitigation-vulnerability | Issue Tracking |
| https://github.com/absholi7ly/POC-CVE-2025-24813/blob/main/README.md | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24813 | Third Party AdvisoryUS Government Resource |
Track CVE-2025-24813 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24813), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.