Target Industry

Indiscriminate, opportunistic targeting.

Overview

CVE-2025-24813 is identified as a critical security vulnerability within Apache Tomcat. The root cause of this vulnerability lies in the improper implementation of the partial PUT method in Tomcat. This flaw permits an unauthenticated attacker to potentially upload a malicious serialized payload to a server running the affected versions. 

The scope of impact is considerable, particularly for Apache Tomcat servers operating under the specified versions and becomes more critical under certain conditions. Notably, the existence of a proof of concept (PoC) and documented instances of active exploitation underscore the urgency for immediate remediation. 

Organisations utilising the affected versions of Apache Tomcat must prioritise addressing this vulnerability to mitigate the risk of unauthorised access and potential compromise of their systems.

Impact

The vulnerability is an issue related to the implementation of the partial PUT method in Tomcat. When a file is uploaded via a partial PUT request, the server generates a temporary file based on the provided filename. The vulnerability arises when the file’s path separator is replaced by a period (“.”). This seemingly minor behaviour can lead to significant unintended file manipulations, opening the door to two primary exploit scenarios. 

First, there is the risk of information disclosure or corruption. If an attacker uploads a file to a directory that is supposed to be protected, they might gain access to sensitive files or inject malicious content into them. This could compromise the integrity of the files or lead to the leakage of confidential information, undermining the security and privacy of the data stored on the server. 

Second, the vulnerability can enable remote code execution (RCE). Under certain conditions, including default settings for session persistence and the presence of vulnerable libraries, an attacker can execute remote code on the server. This exploit scenario enables the attacker to gain full control over the affected system, potentially leading to further malicious activities such as deploying malware, altering system configurations, or exfiltrating sensitive data. 

Vulnerability Detection

It is strongly advised to apply the latest security patches provided by the Apache Software Foundation and to review security configurations to ensure robust protection against such vulnerabilities. Systems utilising any of the following versions of Apache Tomcat are vulnerable to CVE-2025-24813: 

  • Apache Tomcat 11.0.0-M1 to 11.0.2 
  • Apache Tomcat 10.1.0-M1 to 10.1.34 
  • Apache Tomcat 9.0.0-M1 to 9.0.98 

Exploitation

The vulnerability is being actively exploited in the wild, and this has been reported by multiple sources. One proof-of-concept exploit is available on GitHub. 

Containment, Mitigations & Remediation

Users should ensure they are running Apache Tomcat 11.0.3 or later, Apache Tomcat 10.1.35 or later, or Apache Tomcat 9.0.99 or later.  

  1. If immediate upgrading is not feasible, administrators should disable features such as the partial PUT method and restrict write access to sensitive files and directories as a temporary risk mitigation measure.  
  2. Additionally, it is essential to implement stronger security protocols, including appropriate file permissions, securing sensitive data, and updating all dependencies to their secure versions.  

Threat Landscape

Apache Tomcat is a widely used open-source implementation of the Java Servlet, JavaServer Pages (JSP), and Java Expression Language (EL) technologies. It serves as a robust and flexible web server and servlet container, allowing developers to build and deploy dynamic web applications. Apache Tomcat is utilised by numerous organisations across various sectors, including technology, finance, healthcare, and education, due to its reliability and scalability. Thousands of companies worldwide, ranging from small startups to large enterprises, rely on Tomcat for their web infrastructure, making it a cornerstone in the deployment of Java-based applications. 

Threat Group

No attribution to recent specific threat actors or groups has been identified at the time of writing.  

Further Information

  1. Malware News article 
  2. Apache bulletin 
  3. CyberMaxx article
  4. Apache Tomcat Proof of Concept on GitHub 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content