{"id":2666,"date":"2025-03-18T10:05:11","date_gmt":"2025-03-18T10:05:11","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/critical-apache-tomcat-rce-vulnerability-exploited-in-just-30hrs-of-public-exploit\/"},"modified":"2025-03-18T10:05:11","modified_gmt":"2025-03-18T10:05:11","slug":"critical-apache-tomcat-rce-vulnerability-exploited-in-just-30hrs-of-public-exploit","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/03\/18\/critical-apache-tomcat-rce-vulnerability-exploited-in-just-30hrs-of-public-exploit\/","title":{"rendered":"Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit"},"content":{"rendered":"<p>    Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Security researchers have confirmed that a critical remote code execution (RCE) vulnerability in Apache Tomcat, tracked as <a href=\"https:\/\/cybersecuritynews.com\/tomcat-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-24813<\/a>, is being actively exploited in the wild.<\/p>\n<p>The vulnerability, which enables attackers to take control of servers with a simple PUT request, was disclosed last week, and proof-of-concept exploits were published on GitHub merely 30 hours later.<\/p>\n<p>The critical flaw affects multiple versions of Apache Tomcat: 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, and 9.0.0.M1 to 9.0.98. First disclosed by Apache on March 10, 2025, the vulnerability allows attackers to view or inject arbitrary content on security-sensitive files under specific conditions.<\/p>\n<p>Wallarm security researchers <a href=\"https:\/\/lab.wallarm.com\/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">have confirmed<\/a> active exploitation attempts, warning that traditional security tools fail to detect these attacks because the PUT requests appear normal and malicious content is obfuscated using base64 encoding.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi6wFbHgP8y8N9D588Eu2G-q4dng7c-9DXPjFyiRpwga8wGe31py2UqxLtm3_zCof8TuEBXqKlHtq_sqO6I6ZpQBCANRHM2j7KF6JFWc0vNGwe5P3GEePBo4mUuujMF8LRzrv_IP6w2q0mzQt0H3gnYdDzPWhr52tCOvk4QryqlORaLM853ifsao0Ep1S6n\/s16000\/apache%2520tomcat.webp?ssl=1\" alt=\"\"><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Exploitation Mechanism<\/strong><\/h2>\n<p>The attack leverages Tomcat\u2019s default session persistence mechanism along with its support for partial PUT requests in a two-step process:<\/p>\n<h3 class=\"wp-block-heading\"><strong>Step 1: Uploading Malicious Code<\/strong><\/h3>\n<p>The attacker sends a PUT request containing a base64-encoded serialized Java payload, which gets saved to Tomcat\u2019s session storage. This request appears innocuous to most security filters, as the malicious payload is effectively hidden through encoding.<\/p>\n<h3 class=\"wp-block-heading\"><strong>Step 2: Triggering Execution<\/strong><\/h3>\n<p>Once the malicious file is uploaded, the attacker sends a GET request with a JSESSIONID cookie pointing to the uploaded session file. This forces Tomcat to deserialize and execute the malicious Java code, granting complete control to the attacker.<\/p>\n<p>\u201cThis attack is dead simple to execute and requires no authentication,\u201d explains Wallarm in their analysis. \u201cThe only requirement is that Tomcat is using file-based session storage, which is common in many deployments.\u201d<\/p>\n<p>Traditional Web Application Firewalls (WAFs) struggle to detect this attack for several reasons:<\/p>\n<ol class=\"wp-block-list\">\n<li>The initial PUT request looks normal without obvious malicious signatures<\/li>\n<li>Base64 encoding enables the payload to bypass pattern-based detection<\/li>\n<li>The attack unfolds in multiple steps, with execution occurring during deserialization<\/li>\n<li>Most security tools don\u2019t deeply inspect uploaded files or track multi-step attacks.<\/li>\n<\/ol>\n<p>User iSee857 <a href=\"https:\/\/github.com\/iSee857\/CVE-2025-24813-PoC\/blob\/main\/Tomcat_CVE-2025-24813_RCE.py\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">created a GitHub<\/a> repository containing exploit code. The repository features a Python script that can check for vulnerability across multiple targets.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Mitigations<\/strong><\/h2>\n<p>Apache recommends that all users upgrade to Tomcat versions 11.0.3+, 10.1.35+, or 9.0.99+, which contain patches for <a href=\"https:\/\/cybersecuritynews.com\/apache-tomcat-vulnerability-rce-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-24813<\/a>.<\/p>\n<p>For organizations unable to update immediately, alternative mitigations include:<\/p>\n<ul class=\"wp-block-list\">\n<li>Reverting to the default servlet configuration (readonly=\u201dtrue\u201d)<\/li>\n<li>Turning off partial PUT support<\/li>\n<li>Avoiding storing security-sensitive files in subdirectories of public upload paths<\/li>\n<\/ul>\n<p>Security experts warn that this is likely just the beginning, as attackers will soon evolve their tactics beyond session storage exploitation. \u201cAttackers will soon start shifting their tactics, uploading malicious JSP files, modifying configurations, and planting backdoors outside session storage. This is just the first wave,\u201d cautions Wallarm.<\/p>\n<p>The rapid exploitation of this vulnerability highlights the critical importance of proactive security measures and prompt patching in today\u2019s threat landscape.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><strong><code><strong>Are you from SOC\/DFIR Teams? \u2013 Analyse Malware Incidents &amp; get live Access with ANY.RUN -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=ti_feeds&amp;utm_content=demo&amp;utm_term=110325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start Now for Free<\/a>.<\/strong><\/code><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apache-tomcat-rce-vulnerability-exploited\/\">Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apache-tomcat-rce-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit Security researchers have confirmed that a critical remote code execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813, is being actively exploited in the wild. The vulnerability, which enables attackers to take control of servers with a simple PUT request, was disclosed last [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-2666","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2666"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2666"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2666\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}