REDHAT-BUG-2457025: Input Validation
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.20 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.53 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.116
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2457025?
The vulnerability REDHAT-BUG-2457025 is classified as a moderate severity issue due to improper input validation.
How do I fix REDHAT-BUG-2457025?
To resolve REDHAT-BUG-2457025, upgrade Apache Tomcat to versions 11.0.20, 10.1.53, or 9.0.116.
Which versions of Apache Tomcat are affected by REDHAT-BUG-2457025?
Apache Tomcat versions 11.0.15 to 11.0.19, 10.1.50 to 10.1.52, and 9.0.113 to 9.0.115 are affected by REDHAT-BUG-2457025.
What type of vulnerability is REDHAT-BUG-2457025?
REDHAT-BUG-2457025 is an improper input validation vulnerability.
Is there a known exploit for REDHAT-BUG-2457025?
Currently, there is no public knowledge of an exploit specifically targeting REDHAT-BUG-2457025.