https://seclists.org/oss-sec/2025/q2/184: CVE-2025-46701: Apache Tomcat: Security constraint bypass for CGI scripts
Published May 29, 2025
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M1<=11.0.6
Apache Tomcat>=10.1.0-M1<=10.1.40
Apache Tomcat>=9.0.0.M1<=9.0.104
Frequently Asked Questions
1
What is the severity of CVE-2025-46701?
The severity of CVE-2025-46701 is classified as low.
2
Which Apache Tomcat versions are affected by CVE-2025-46701?
CVE-2025-46701 affects Apache Tomcat versions 11.0.0-M1 through 11.0.6, 10.1.0-M1 through 10.1.40, and 9.0.0.M1 through 9.0.104.
3
How do I fix CVE-2025-46701?
To fix CVE-2025-46701, you should upgrade to the latest stable version of Apache Tomcat that is not affected by this vulnerability.
4
What type of vulnerability is CVE-2025-46701?
CVE-2025-46701 is a security constraint bypass vulnerability specifically for CGI scripts in Apache Tomcat.
5
Who discovered CVE-2025-46701?
CVE-2025-46701 was discovered by Greg K.