logo

Apache Tomcat: CVE-2025-24813

ID: 0fd6858d-c785-5a15-bba3-152c4323c3a7

STIX ID: report--0fd6858d-c785-5a15-bba3-152c4323c3a7

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2025-03-28

Date Updated: 2026-04-28

...
...

CVE-2025-24813 is a critical Apache Tomcat path-equivalence vulnerability that can allow unauthenticated remote code execution and file injection when specific conditions are met (default servlet write enabled, partial PUT enabled, file-based session persistence, and an exploitable deserialization gadget). Recorded Future’s Insikt Group details exploitation steps (malicious Base64 PUT followed by GET with crafted JSESSIONID), notes published PoCs and observed scanning attempts from multiple IPs, lists IoCs (unexpected JSPs, PUT requests, malicious payloads), reports ~378k exposed Tomcat instances on Shodan, and recommends upgrading Tomcat or applying network restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.