Untrusted search path in Apache Tomcat - CVE-2025-49124
Published: June 16, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path in the application's installer on Windows. A local user can place a malicious binary icacls.exe into the current working directory of the installer file end execute arbitrary code with elevated privileges.
Note, the vulnerability affects Windows systems only.
Affected software
Netcool Operations Insight
EasyApache
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Storage Protect Plus Server
How to mitigate CVE-2025-49124
Netcool Operations Insight - update to 1.6.15
EasyApache - update to 4 25-20
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Storage Protect Plus Server - update to 10.1.18
External References
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.42
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.106
- https://github.com/apache/tomcat/commit/c56456cda8151c9504dfb7985700824559d769a7
- https://github.com/apache/tomcat/commit/e0e07812224d327a321babb554f5a5758d30cc49
- https://github.com/apache/tomcat/commit/28726cc2e63bed68771f5eb0f65a78dc7080571823
- https://lists.apache.org/thread/p201jp4to0nr4ky9h3j97ywk2zqv185m
Related Security Bulletins
- Multiple vulnerabilities in Apache Tomcat
- cPanel EasyApache4 update for Apache Tomcat
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in IBM Storage Protect Plus Server
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition