HomeSecurityHackers exploit Apache Tomcat RCE vulnerability

Hackers exploit Apache Tomcat RCE vulnerability

Attackers are actively exploiting a critical vulnerability in Apache Tomcat, tracked as CVE-2025-24813, which could allow unauthorized remote code execution (RCE) on vulnerable servers.

See also: RCE vulnerability in Apache Struts 2 puts servers at risk

Apache Tomcat RCE

The vulnerability, which was first disclosed on March 10, 2025, has already suffered exploitation attempts that began just 30 hours after the PoC was publicly released.

GreyNoise Intelligence has identified four unique IP addresses attempting to exploit this vulnerability since March 17, 2025, with exploitation attempts observed as early as March 11.

These attackers exploit a partial PUT method to inject malicious payloads, which could potentially lead to arbitrary code execution on affected systems.

The root cause of the RCE vulnerability lies in the way Apache Tomcat handles file paths during some PUT requests.

See also: Vulnerability in Apache Tomcat allows Dos attacks

When a user uploads a file, Tomcat creates a temporary file using the specified file name and path, replacing the path separators with periods.

Hackers exploit Apache Tomcat RCE vulnerability

This approach, originally designed as a security measure against path-based navigation, inadvertently opened a new vulnerability. The Apache Tomcat RCE exploit involves two key steps: first, an attacker sends a PUT request to upload a specially crafted Java session file, spoofing the file name and path in order to exploit the path equivalence vulnerability.

Second, the attacker triggers deserialization of the uploaded file by sending a GET request referring to the malicious session ID, which can lead to remote code execution.

The vulnerability affects multiple versions of Apache Tomcat:

  • Apache Tomcat 11.0.0-M1 to 11.0.2
  • Apache Tomcat 10.1.0-M1 to 10.1.34
  • Apache Tomcat 9.0.0-M1 to 9.0.98

See also: Apache Roller CSRF vulnerability allows privilege escalation

Remote Code Execution (RCE ) refers to a class of security vulnerabilities that allow an attacker to execute arbitrary code on a remote computer or system over a network. This vulnerability can occur in applications or services that do not properly handle data input or that allow code execution without proper security checks.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS