https://seclists.org/oss-sec/2025/q1/197: CVE-2025-24813: Apache Tomcat: Potential RCE and/or information disclosuand/or information corruption with partial PUT
Published Mar 10, 2025
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M1<=11.0.2
Apache Tomcat>=10.1.0-M1<=10.1.34
Apache Tomcat>=9.0.0.M1<=9.0.98
Frequently Asked Questions
1
What is the severity of CVE-2025-24813?
CVE-2025-24813 is classified as having an important severity level.
2
Which Apache Tomcat versions are affected by CVE-2025-24813?
CVE-2025-24813 affects Apache Tomcat versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, and 9.0.0.M1 through 9.0.98.
3
How can I mitigate the risk of CVE-2025-24813?
To mitigate CVE-2025-24813, ensure that the default servlet writes are disabled and consider disabling partial PUT support.
4
What types of attacks can CVE-2025-24813 potentially facilitate?
CVE-2025-24813 has the potential to facilitate remote code execution, information disclosure, and information corruption.
5
Is there a fix available for CVE-2025-24813?
Yes, upgrading to the latest patched version of Apache Tomcat resolves the vulnerability identified as CVE-2025-24813.