Expected behavior violation in Apache HTTP Server - CVE-2025-54090

 

Expected behavior violation in Apache HTTP Server - CVE-2025-54090

Published: July 23, 2025


Vulnerability identifier: #VU113185
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54090
CWE-ID: CWE-440
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in code that causes the "RewriteCond expr" to be always "true". A remote attacker can bypass implemented security restrictions that rely on regular expressions. 


Affected software

Apache HTTP Server
IBM HTTP Server
SecurityCenter
Communications Unified Assurance
WebSphere Remote Server
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Business Automation Workflow
Oracle Communications Cloud Native Core Automated Test Suite
DevOps Code ClearCase
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Oracle Communications Cloud Native Core Unified Data Repository

How to mitigate CVE-2025-54090

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.65
SecurityCenter - addressed in versions SC-202602.1, SC-202602.2
IBM HTTP Server - update to 9.0.5.25

External References

Related Security Bulletins