CVE-2025-24813
Apache Tomcat Path Equivalence Vulnerability
A Rapid Response card and targeted test have been released for CVE-2025-24813 against Apache Tomcat. The vulnerability uses deserialization of untrusted data that enables an unauthenticated attacker to upload arbitrary files and potentially perform remote code execution. The attack requires a non-default configuration of Apache Tomcat but the configuration changes are common enough that it is being actively exploited in the wild.
Recommended mitigations are to update to Apache Tomcat versions 11.0.3, 10.1.35 or 9.0.99 depending on the version currently deployed in the client environment.
Rapid Response N-Day Testing
