PT-2025-43996 · Apache+9 · Apache Tomcat+9

CVE-2025-55752

·

Published

2025-09-08

·

Updated

2026-08-03

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.10 Apache Tomcat versions 10.1.0-M1 through 10.1.44 Apache Tomcat versions 9.0.0.M11 through 9.0.108 Apache Tomcat versions 8.5.6 through 8.5.100
Description A relative path traversal issue exists due to a regression where rewritten URLs are normalized before being decoded. This allows an attacker to manipulate the request URI to bypass security constraints, granting unauthorized access to protected directories such as '/WEB-INF/' and '/META-INF/'. If the PUT method is enabled, this could allow the upload of malicious files, potentially leading to remote code execution. This issue specifically occurs when rewrite rules are used to rewrite query parameters to the URL, often involving the RewriteValve component.
Recommendations Upgrade to version 11.0.11 or later. Upgrade to version 10.1.45 or later. Upgrade to version 9.0.109 or later. Disable RewriteValve entries in server.xml or context.xml where not strictly required. Disable the PUT method to prevent potential remote code execution.

Exploit

Fix

DoS

RCE

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:23048
ALSA-2025:23049
ALSA-2025:23050
ALSA-2025:23052
ALSA-2025_16880
ALT-PU-2025-13135
ALT-PU-2025-14452
BDU:2025-13742
BIT-TOMCAT-2025-55752
CVE-2025-55752
GHSA-WMWF-9CCG-FFF5
MGASA-2025-0250
OESA-2025-2559
OESA-2025-2560
OESA-2025-2561
OESA-2025-2562
OESA-2025-2563
OESA-2025-2630
OPENSUSE-SU-2025:15716-1
OPENSUSE-SU-2025:15717-1
OPENSUSE-SU-2025:15718-1
OPENSUSE-SU-2025:20106-1
OPENSUSE-SU-2026:20034-1
OPENSUSE-SU-2026:20444-1
RHSA-2025:19809
RHSA-2026:0292
RHSA-2026:0293
RHSA-2026:2724
RHSA-2026:2725
RHSA-2026:2726
RHSA-2026:6569
RHSA-2026:8334
SUSE-SU-2025:21152-1
SUSE-SU-2025:4086-1
SUSE-SU-2025:4103-1
SUSE-SU-2025:4159-1
SUSE-SU-2025:4184-1
SUSE-SU-2025_21152-1
SUSE-SU-2025_4086-1
SUSE-SU-2025_4103-1
SUSE-SU-2025_4159-1
SUSE-SU-2025_4184-1
SUSE-SU-2026:1058-1
SUSE-SU-2026:20084-1
SUSE-SU-2026:20982-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Bitbucket
Centos
Debian
Red Hat
Red Os
Rocky Linux
Suse