'Dead simple' hijacking hole in Apache Tomcat 'now actively exploited in the wild'
ID: add0e2b7-7abf-50d6-9371-8fe1972eb9f9
STIX ID: report--add0e2b7-7abf-50d6-9371-8fe1972eb9f9
Feed Name: The Register (Security)
The report details CVE-2025-24813, an Apache Tomcat unauthenticated remote code execution and file-access vulnerability exploitable when Tomcat uses file-based session storage: an attacker can upload a malicious session file via HTTP PUT (containing a base64 ysoserial gadget chain) and then trigger deserialization by issuing a GET with a crafted JSESSIONID. A public exploit was published ~30 hours after disclosure and active exploitation has been observed in the wild (reported attribution to Chinese operators); affected versions and required configuration conditions are listed, and Apache notes most installations likely will not be vulnerable due to the specific prerequisites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
