• News/
  • https://www.bleepingcomputer.com/news/security/critical-rce-flaw-in-apache-tomcat-actively-exploited-in-attacks/

Critical RCE flaw in Apache Tomcat actively exploited in attacks

BleepingComputer
·
Bill Toulas
·
Published Mar 17, 2025
·
Updated

A critical remote code execution (RCE) vulnerability in Apache Tomcat tracked as CVE-2025-24813 is actively exploited in the wild, enabling attackers to take over servers with a simple PUT request. Hackers are reportedly leveraging proof-of-concept (PoC) exploits that were published on GitHub just 30 hours after the flaw was disclosed last week. The malicious activity was confirmed by Wallarm security researchers, who warned that traditional security tools fail to detect it as PUT requests appear normal and the malicious content is obfuscated using base64 encoding. Specifically, the attacker sends a PUT request containing a base64-encoded serialized Java payload saved to Tomcat's session storage. The attacker then sends a GET request with a JSESSIONID cookie pointing to the uploaded session file, forcing Tomcat to deserialize and execute the malicious Java code, granting complete control to the attacker. The attack does not require authentication and is caused by Tomcat accepting partial PUT requests and its default session persistence. "This attack is dead simple to execute and requires no authentication," explains Wallarm. "The only requirement is that Tomcat is using file-based session storage, which is common in many deployments. Worse, base64 encoding allows the exploit to bypass most traditional security filters, making detection challenging." The CVE-2025-24813 remote code execution vulnerability flaw was first disclosed by Apache on March 10, 2025, impacting Apache T...

Read full article

Affected Software

8 affected components
Apache Tomcat=11.0.0-M1
Apache Tomcat=11.0.1
Apache Tomcat=11.0.2
Apache Tomcat=10.1.0-M1
Apache Tomcat=10.1.34
Apache Tomcat=9.0.0.M1
Apache Tomcat=9.0.98
Apache Tomcat

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in Apache Tomcat, identified as CVE-2025-24813, that is actively exploited by attackers.

2

What are the security implications of the CVE-2025-24813 vulnerability?

The vulnerability allows attackers to take control of servers with a simple PUT request, posing a significant security risk.

3

Which versions of Apache Tomcat are affected by this vulnerability?

The affected versions include Apache Tomcat 11.0.0-M1, 11.0.1, 11.0.2, 10.1.0-M1, 10.1.34, 9.0.0.M1, and 9.0.98.

4

How can organizations protect themselves from this Apache Tomcat vulnerability?

Organizations should update their Apache Tomcat installations to the latest versions that include patches for the vulnerability.

5

Who is responsible for addressing the CVE-2025-24813 vulnerability?

The responsibility lies with the Apache Software Foundation to provide security updates and guidance for their Tomcat software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203