icon

We found results for “

CVE-2025-49124

Good to know:

icon

Date: June 16, 2025

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Untrusted Search Path

CWE-426

Top Fix

icon

Upgrade Version

Upgrade to version org.apache.tomcat.embed:tomcat-embed-core:11.0.8;org.apache.tomcat.embed:tomcat-embed-core:10.1.42;org.apache.tomcat.embed:tomcat-embed-core:9.0.106;org.apache.tomcat:tomcat:11.0.8;org.apache.tomcat:tomcat:10.1.42;org.apache.tomcat:tomcat:9.0.106;org.apache.tomcat:tomcat-catalina:11.0.8;org.apache.tomcat:tomcat-catalina:10.1.42;org.apache.tomcat:tomcat-catalina:9.0.106;https://github.com/apache/tomcat.git - 9.0.106;https://github.com/apache/tomcat.git - 10.1.42;https://github.com/apache/tomcat.git - 11.0.8;https://github.com/apache/tomcat.git - https://github.com/apache/tomcat/commit/05ccf0c3e22d388f0cf853e32485d8249d051f2f

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us