216.73.216.6

Apache Tomcat: CVE-2025-24813: Active Exploitation

· Published 28/03/2025 15:56 · Modified 31/03/2025 11:26

Export JSON

Essential information

Published
28/03/2025 15:56
Modified
31/03/2025 11:26
Tags
2025-03-28 CVE-2025-24813 apache tomcat exploitation patching path equivalence remote code execution vulnerability
Related entities
8 techniques (mitre), 12 others

Description

A critical in , , allows unauthenticated attackers to execute arbitrary code on vulnerable servers under specific conditions. The affects Tomcat versions 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0.M1 to 9.0.98, and certain 8.5.x versions. requires specific server configurations and involves sending malicious PUT and GET requests. Six malicious IP addresses have been identified attempting to exploit this , targeting systems in the US, Japan, Mexico, South Korea, and Australia. Multiple proof-of-concept exploits have been published, increasing the likelihood of ongoing attempts. Users are advised to upgrade to patched versions or implement network-level controls to restrict access to the Tomcat server.

External references