logo

CVE-2025-24813: Apache Tomcat Vulnerability

ID: 7fa4c3a2-ab02-59af-b869-e351d2b0afb1

STIX ID: report--7fa4c3a2-ab02-59af-b869-e351d2b0afb1

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-05-22

Date Updated: 2026-05-01

...
...

This report describes CVE-2025-24813 affecting Apache Tomcat: an attacker can upload a malicious Java session file via HTTP PUT into Tomcat's session storage and then trigger its deserialization by sending a GET request with a crafted JSESSIONID cookie, resulting in remote code execution and potential data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.