Apache Tomcat: CVE-2025-24813
ID: 0fd6858d-c785-5a15-bba3-152c4323c3a7
STIX ID: report--0fd6858d-c785-5a15-bba3-152c4323c3a7
Feed Name: Recorded Future Blog
CVE-2025-24813 is a critical Apache Tomcat path-equivalence vulnerability that can allow unauthenticated remote code execution and file injection when specific conditions are met (default servlet write enabled, partial PUT enabled, file-based session persistence, and an exploitable deserialization gadget). Recorded Future’s Insikt Group details exploitation steps (malicious Base64 PUT followed by GET with crafted JSESSIONID), notes published PoCs and observed scanning attempts from multiple IPs, lists IoCs (unexpected JSPs, PUT requests, malicious payloads), reports ~378k exposed Tomcat instances on Shodan, and recommends upgrading Tomcat or applying network restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
