CVE-2025-24813: Remote Code Execution (RCE) Vulnerability in Apache Tomcat

ISGroup Cybersecurity

CVE-2025-24813 is a critical security vulnerability affecting several versions of Apache Tomcat. The flaw is being actively exploited in the wild, allowing attackers to compromise vulnerable servers. If exploited, it can lead to remote code execution, unauthorized access to sensitive files, and malicious modification of uploaded content. Organizations using affected versions of Tomcat should act immediately to mitigate the risk.

ProductApache Tomcat
Date2025-03-21 09:13:06
Information
  • Fix Available
  • Active Exploitation

Technical Summary

CVE-2025-24813 is a vulnerability in Apache Tomcat that can lead to remote code execution. The issue stems from how Tomcat handles file uploads and session file deserialization. Specifically, when a PUT request is allowed to upload a session file containing a specially crafted serialized payload, the server may subsequently process (or deserialize) this file—often triggered by a GET request (e.g., to /index.jsp). This improper handling of file paths containing internal dots allows an attacker to execute arbitrary code on the server.

Recommendations

  • Update Tomcat: Upgrade to a patched version (11.0.3, 10.1.35, or 9.0.98) to mitigate the vulnerability.
  • Restrict file uploads: Limit or disable PUT requests where possible, or restrict them to trusted directories and users.
  • Input validation: Implement robust validation and sanitization of file names and paths to prevent malicious payloads.
  • Monitor activity: Regularly check server logs for unusual file upload or deserialization activity that may indicate exploitation attempts.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert