CVE-2025-55668
published 2025-08-13CVE-2025-55668: Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.78%
51.5th percentile
Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.0.0 < 10.1.42 | 10.1.42 |
| apache | tomcat | >= 11.0.0 < 11.0.8 | 11.0.8 |
| apache | tomcat | >= 9.0.1 < 9.0.106 | 9.0.106 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.41 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.7 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.105 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve
vendor_redhat·2025-08-13·CVSS 6.5
CVE-2025-55668 [MEDIUM] CWE-384 org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve
org.apache.tomcat/tomcat-catalina: tomcat: Apache Tomcat: session fixation via rewrite valve
Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
A session fixation vulnerability has been identified in Apache Tomcat, affecting its rewrite functionality. If the rewrite valve is enabled for a web application, an attacker can craft a specific URL. If a victim clicks on this malicious URL, their subsequent interaction with the resource will occur within the context of the attacker's session. This could allow an attacker
Debian
CVE-2025-55668: tomcat10 - Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue a...
vendor_debian·2025·CVSS 6.5
CVE-2025-55668 [MEDIUM] CVE-2025-55668: tomcat10 - Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue a...
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.52-1~deb12u1)
forky: resolved (fixed in 10.1.46-1)
sid: resolved (fixed in 10.1.46-1)
trixie: resolved (fixed in 10.1.52-1~deb13u1)
GHSA
Apache Tomcat Session Fixation vulnerability
ghsa·2025-08-13
CVE-2025-55668 [MEDIUM] CWE-384 Apache Tomcat Session Fixation vulnerability
Apache Tomcat Session Fixation vulnerability
Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
OSV
CVE-2025-55668: Session Fixation vulnerability in Apache Tomcat via rewrite valve
osv·2025-08-13·CVSS 6.5
CVE-2025-55668 [MEDIUM] CVE-2025-55668: Session Fixation vulnerability in Apache Tomcat via rewrite valve
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
OSV
Apache Tomcat Session Fixation vulnerability
osv·2025-08-13
CVE-2025-55668 [MEDIUM] Apache Tomcat Session Fixation vulnerability
Apache Tomcat Session Fixation vulnerability
Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
No detection rules found.
No public exploits indexed.
2025-08-13
Published