CVE-2025-55752

CWE-239 documents7 sources
Severity
7.5HIGH
EPSS
0.1%
top 65.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27

Description

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages8 packages

NVDapache/tomcat9.0.19.0.109+5
Mavenorg.apache.tomcat:tomcat11.0.0-M111.0.11+3
Mavenorg.apache.tomcat:tomcat-catalina11.0.0-M111.0.11+3
Mavenorg.apache.tomcat.embed:tomcat-embed-core11.0.0-M111.0.11+3
CVEListV5apache_software_foundation/apache_tomcat11.0.0-M111.0.10+3

🔴Vulnerability Details

4
CVEList
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled2025-10-27
GHSA
Apache Tomcat Vulnerable to Relative Path Traversal2025-10-27
OSV
CVE-2025-55752: Relative Path Traversal vulnerability in Apache Tomcat2025-10-27
OSV
Apache Tomcat Vulnerable to Relative Path Traversal2025-10-27

📋Vendor Advisories

2
Red Hat
tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE2025-10-27
Debian
CVE-2025-55752: tomcat10 - Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 i...2025

💬Community

2
Bugzilla
CVE-2025-55752 tomcat: Apache Tomcat: Directory traversal via rewrite with possible RCE [fedora-42]2025-10-27
Bugzilla
CVE-2025-55752 tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE2025-10-27
CVE-2025-55752 (HIGH CVSS 7.5) | Relative Path Traversal vulnerabili | cvebase.io