CVE-2025-55752 and CVE-2025-55754: Apache Tomcat Vulnerabilities Expose Servers to RCE Attacks
ID: 768d0cfa-d58a-5ee4-acac-31b66c35ffa3
STIX ID: report--768d0cfa-d58a-5ee4-acac-31b66c35ffa3
Feed Name: SOC Prime Blog
This advisory details two newly disclosed Apache Tomcat vulnerabilities affecting multiple 9.x, 10.x, and 11.x releases: CVE-2025-55752 (Important) which allows directory traversal via normalized/rewritten URLs and may enable remote code execution when HTTP PUT is permitted, and CVE-2025-55754 (Low) which permits ANSI escape sequences in console logs that can mislead administrators. The report lists affected versions, recommends upgrading to patched releases (Tomcat 11.0.11, 10.1.45, 9.0.109), and suggests mitigations such as disabling/restricting PUT, reviewing logging configurations, and monitoring for anomalous uploads and log activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
