Improper handling of case sensitivity in Apache Tomcat - CVE-2025-46701

 

Improper handling of case sensitivity in Apache Tomcat - CVE-2025-46701

Published: May 30, 2025 / Updated: March 13, 2026


Vulnerability identifier: #VU109959
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46701
CWE-ID: CWE-178
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to an error when handling URLs on a case insensitive filesystem with security constraints configured for the <code>pathInfo</code> component of a URL that mapped to the CGI servlet. A remote attacker can bypass imposed security constraints via a specially crafted URL.


Affected software

Apache Tomcat
Debian Linux
openEuler
Anolis OS
Ubuntu
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Jira Service Management Server
Bitbucket Data Center
Jira Software Data Center
IBM Power Hardware Management Console (HMC)
NetWorker
Cloudera Observability with IBM
DevOps Solution Workbench
IBM Business Automation Manager Open Editions
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
ApplinX
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
webMethods BPM
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
Jira Software Server
Bitbucket Server
watsonx.data
tomcat-help
tomcat-jsvc
tomcat
tomcat-admin-webapps
tomcat-webapps
tomcat-servlet-4.0-api
tomcat-lib
tomcat-docs-webapp
tomcat-doc
tomcat-jsp-2.3-api
tomcat-el-3.0-api
tomcat10 (Ubuntu package)
tomcat10 (Debian package)
tomcat11 (Debian package)

How to mitigate CVE-2025-46701

Install updates from vendor's website.

Apache Tomcat - addressed in versions 9.0.105, 10.1.41, 11.0.7
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
Jira Service Management Data Center - addressed in versions 5.12.24, 10.3.7, 10.7.1
Jira Service Management Server - addressed in versions 5.12.24, 10.3.7, 10.7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Bitbucket Server - addressed in versions 8.19.20, 9.4.8, 9.6.4
Bitbucket Data Center - addressed in versions 8.19.20, 9.4.8, 9.6.4
IBM Business Automation Manager Open Editions - update to 9.2.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Jira Software Data Center - addressed in versions 9.12.24, 10.3.7, 10.7.1
Jira Software Server - addressed in versions 9.12.24, 10.3.7, 10.7.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
ApplinX - update to 11.1.0 Fix 5
NetWorker - update to 19.13.0.1
watsonx.data - update to 2.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
watsonx Assistant Cartridge - update to 5.2.1
tomcat-help - update to 9.0.100-3
tomcat-jsvc - update to 9.0.100-3
tomcat - update to 9.0.100-3
tomcat-admin-webapps - update to 9.0.115-1
tomcat-webapps - update to 9.0.115-1
tomcat-servlet-4.0-api - update to 9.0.115-1
tomcat - update to 9.0.115-1
tomcat-lib - update to 9.0.115-1
tomcat-docs-webapp - update to 9.0.115-1
tomcat-doc - update to 9.0.115-1
tomcat-jsp-2.3-api - update to 9.0.115-1
tomcat-el-3.0-api - update to 9.0.115-1
tomcat10 (Ubuntu package) - addressed in versions 10.1.16-1ubuntu0.1~esm3, 10.1.35-1ubuntu0.1
tomcat10 (Debian package) - addressed in versions 10.1.52-1~deb12u1, 10.1.52-1~deb13u1
webMethods BPM - addressed in versions 10.15 Fix 14, 11.1 Fix 2
tomcat11 (Debian package) - update to 11.0.15-1~deb13u1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins