Session Fixation in Apache Tomcat - CVE-2025-55668

 

Session Fixation in Apache Tomcat - CVE-2025-55668

Published: August 26, 2025


Vulnerability identifier: #VU114443
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55668
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to session fixation. A remote attacker can trick the victim into opening a specially crafted request to gain unauthorized access to sensitive information on the system.


Affected software

Apache Tomcat
Debian Linux
openEuler
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Cloudera Observability with IBM
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
webMethods BPM
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
tomcat
tomcat-jsvc
tomcat-help
tomcat10 (Debian package)
tomcat11 (Debian package)

How to mitigate CVE-2025-55668

Install updates from vendor's website.

Apache Tomcat - addressed in versions 9.0.106, 10.1.42, 11.0.8
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
tomcat - update to 9.0.100-8
tomcat-jsvc - update to 9.0.100-8
tomcat-help - update to 9.0.100-8
tomcat10 (Debian package) - addressed in versions 10.1.52-1~deb12u1, 10.1.52-1~deb13u1
webMethods BPM - addressed in versions 10.15 Fix 14, 11.1 Fix 2
tomcat11 (Debian package) - update to 11.0.15-1~deb13u1

External References

Related Security Bulletins