Metrics
Affected Vendors & Products
Wed, 02 Jul 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache tomcat |
|
CPEs | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache tomcat |
Tue, 17 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|
Tue, 17 Jun 2025 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Mon, 16 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 16 Jun 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. | |
Title | Apache Tomcat: Security constraint bypass for pre/post-resources | |
Weaknesses | CWE-288 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-17T14:06:56.975Z
Reserved: 2025-06-02T09:08:38.126Z
Link: CVE-2025-49125

Updated: 2025-06-16T20:03:25.368Z

Status : Analyzed
Published: 2025-06-16T15:15:24.850
Modified: 2025-07-02T18:28:13.577
Link: CVE-2025-49125
