CVE-2025-49124

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
References
Link Resource
https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/06/16/3 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

History

02 Jul 2025, 18:28

Type Values Removed Values Added
References () https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv - () https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/06/16/3 - () http://www.openwall.com/lists/oss-security/2025/06/16/3 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
First Time Apache
Apache tomcat

17 Jun 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de ruta de búsqueda no confiable en el instalador de Apache Tomcat para Windows. Durante la instalación, el instalador de Tomcat para Windows utilizó icacls.exe sin especificar una ruta completa. Este problema afecta a Apache Tomcat: de 11.0.0-M1 a 11.0.7, de 10.1.0 a 10.1.41, y de 9.0.23 a 9.0.105. Se recomienda actualizar a las versiones 11.0.8, 10.1.42 o 9.0.106, que solucionan el problema.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4

16 Jun 2025, 20:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2025/06/16/3 -

16 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 15:15

Updated : 2025-07-02 18:28


NVD link : CVE-2025-49124

Mitre link : CVE-2025-49124

CVE.ORG link : CVE-2025-49124


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-426

Untrusted Search Path