Expected behavior violation in Apache HTTP Server - CVE-2025-54090
Published: July 23, 2025
Vulnerability identifier: #VU113185
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54090
CWE-ID: CWE-440
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an error in code that causes the "RewriteCond expr" to be always "true". A remote attacker can bypass implemented security restrictions that rely on regular expressions.
Affected software
Apache HTTP Server
IBM HTTP Server
SecurityCenter
Communications Unified Assurance
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
DevOps Code ClearCase
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
IBM HTTP Server
SecurityCenter
Communications Unified Assurance
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
DevOps Code ClearCase
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository
How to mitigate CVE-2025-54090
Install updates from vendor's website.
Apache HTTP Server - update to 2.4.65
SecurityCenter - addressed in versions SC-202602.1, SC-202602.2
IBM HTTP Server - update to 9.0.5.25
SecurityCenter - addressed in versions SC-202602.1, SC-202602.2
IBM HTTP Server - update to 9.0.5.25
External References
Related Security Bulletins
- Security restrictions bypass in Apache HTTP Server
- IBM HTTP Server update for Apache HTTP Server
- Expected behavior violation in IBM Business Automation Workflow
- Expected behavior violation in IBM Rational ClearQuest
- Expected behavior violation in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM DevOps Code ClearCase
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Service Communication Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Expected behavior violation in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Tenable Security Center