#VU111159 Improper Protection of Alternate Path in Apache Tomcat - CVE-2025-49125
Published: June 16, 2025 / Updated: July 16, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to improper access restrictions when using PreResources or PostResources mounted other than at the root of the web application. A remote attacker can bypass configured security rules using a alternate path and gain unauthorized access to the application.
Remediation
External links
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.42
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.106
- https://github.com/apache/tomcat/commit/d94bd36fb7eb32e790dae0339bc249069649a637
- https://github.com/apache/tomcat/commit/7617b9c247bc77ed0444dd69adcd8aa48777886c
- https://github.com/apache/tomcat/commit/9418e3ff9f1f4c006b4661311ae9376c52d162b9
- https://lists.apache.org/thread/gp5rzzqnp7q71bm7lsvxoow89nz1tkjw
- https://lists.apache.org/thread/n7f5v6fzovfxkpqf5q0cztqqn0kjjs4p