Improper handling of case sensitivity in Apache Tomcat - CVE-2025-46701
Published: May 30, 2025 / Updated: March 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to an error when handling URLs on a case insensitive filesystem with security constraints configured for the <code>pathInfo</code> component of a URL that mapped to the CGI servlet. A remote attacker can bypass imposed security constraints via a specially crafted URL.
Affected software
Debian Linux
openEuler
Anolis OS
Ubuntu
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Jira Service Management Server
Bitbucket Data Center
Jira Software Data Center
IBM Power Hardware Management Console (HMC)
NetWorker
Cloudera Observability with IBM
DevOps Solution Workbench
IBM Business Automation Manager Open Editions
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
ApplinX
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
webMethods BPM
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
Jira Software Server
Bitbucket Server
watsonx.data
tomcat-help
tomcat-jsvc
tomcat
tomcat-admin-webapps
tomcat-webapps
tomcat-servlet-4.0-api
tomcat-lib
tomcat-docs-webapp
tomcat-doc
tomcat-jsp-2.3-api
tomcat-el-3.0-api
tomcat10 (Ubuntu package)
tomcat10 (Debian package)
tomcat11 (Debian package)
How to mitigate CVE-2025-46701
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.2.1
Jira Service Management Data Center - addressed in versions 5.12.24, 10.3.7, 10.7.1
Jira Service Management Server - addressed in versions 5.12.24, 10.3.7, 10.7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Bitbucket Server - addressed in versions 8.19.20, 9.4.8, 9.6.4
Bitbucket Data Center - addressed in versions 8.19.20, 9.4.8, 9.6.4
IBM Business Automation Manager Open Editions - update to 9.2.1
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Jira Software Data Center - addressed in versions 9.12.24, 10.3.7, 10.7.1
Jira Software Server - addressed in versions 9.12.24, 10.3.7, 10.7.1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
ApplinX - update to 11.1.0 Fix 5
NetWorker - update to 19.13.0.1
watsonx.data - update to 2.2.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
watsonx Assistant Cartridge - update to 5.2.1
tomcat-help - update to 9.0.100-3
tomcat-jsvc - update to 9.0.100-3
tomcat - update to 9.0.100-3
tomcat-admin-webapps - update to 9.0.115-1
tomcat-webapps - update to 9.0.115-1
tomcat-servlet-4.0-api - update to 9.0.115-1
tomcat - update to 9.0.115-1
tomcat-lib - update to 9.0.115-1
tomcat-docs-webapp - update to 9.0.115-1
tomcat-doc - update to 9.0.115-1
tomcat-jsp-2.3-api - update to 9.0.115-1
tomcat-el-3.0-api - update to 9.0.115-1
tomcat10 (Ubuntu package) - addressed in versions 10.1.16-1ubuntu0.1~esm3, 10.1.35-1ubuntu0.1
tomcat10 (Debian package) - addressed in versions 10.1.52-1~deb12u1, 10.1.52-1~deb13u1
webMethods BPM - addressed in versions 10.15 Fix 14, 11.1 Fix 2
tomcat11 (Debian package) - update to 11.0.15-1~deb13u1
Links to Public Exploits and PoC-codes
External References
- https://lists.apache.org/thread/qyrz13o6960cfg33tz9ghld647884kvd
- https://github.com/apache/tomcat/commit/fab7247d2f0e3a29d5daef565f829f383e10e5e2
- https://github.com/apache/tomcat/commit/0f01966eb60015d975525019e12a087f05ebf01a
- https://github.com/apache/tomcat/commit/2c6800111e7d8d8d5403c07978ea9bff3db5a5a5
- https://github.com/apache/tomcat/commit/238d2aa54b99f91d1111467e2237d2244c64e558
- https://github.com/apache/tomcat/commit/8df00018a252baa9497615d6420fb6c10466fa74
- https://github.com/apache/tomcat/commit/8cb95ff03221067c511b3fa66d4f745bc4b0a605
Related Security Bulletins
- Security restrictions bypass in Apache Tomcat
- openEuler update for tomcat
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM ApplinX
- Jira Software Data Center and Server update for tomcat-catalina
- Bitbucket Data Center and Server update for tomcat-embed-core
- Jira Service Management Data Center and Server update for tomcat-catalina
- Ubuntu update for tomcat10
- IBM Watson Discovery update for Apache Tomcat
- IBM watsonx.data update for Apache Tomcat
- Dell NetWorker update for Apache Tomcat
- Multiple vulnerabilities in IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge
- Multiple vulnerabilities in IBM DevOps Solution Workbench
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Power HMC
- Multiple vulnerabilities in Netcool Operations Insight
- Debian update for tomcat10
- Debian update for tomcat11
- Multiple vulnerabilities in IBM webMethods BPM
- Anolis OS update for tomcat
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in IBM Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition