Session Fixation in Apache Tomcat - CVE-2025-55668
Published: August 26, 2025
Vulnerability identifier: #VU114443
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55668
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to session fixation. A remote attacker can trick the victim into opening a specially crafted request to gain unauthorized access to sensitive information on the system.
Affected software
Apache Tomcat
Debian Linux
openEuler
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Cloudera Observability with IBM
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
webMethods BPM
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
tomcat
tomcat-jsvc
tomcat-help
tomcat10 (Debian package)
tomcat11 (Debian package)
Debian Linux
openEuler
Netcool Operations Insight
IBM Power Hardware Management Console (HMC)
Cloudera Observability with IBM
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
webMethods BPM
Cloudera Data Platform Private Cloud Base for IBM
IBM Qradar SIEM
tomcat
tomcat-jsvc
tomcat-help
tomcat10 (Debian package)
tomcat11 (Debian package)
How to mitigate CVE-2025-55668
Install updates from vendor's website.
Apache Tomcat - addressed in versions 9.0.106, 10.1.42, 11.0.8
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
tomcat - update to 9.0.100-8
tomcat-jsvc - update to 9.0.100-8
tomcat-help - update to 9.0.100-8
tomcat10 (Debian package) - addressed in versions 10.1.52-1~deb12u1, 10.1.52-1~deb13u1
webMethods BPM - addressed in versions 10.15 Fix 14, 11.1 Fix 2
tomcat11 (Debian package) - update to 11.0.15-1~deb13u1
Netcool Operations Insight - update to 1.6.15
Cloudera Observability with IBM - update to 3.6.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
IBM Power Hardware Management Console (HMC) - addressed in versions 10.3.1060.0 SP3, 11.1.1110.0
tomcat - update to 9.0.100-8
tomcat-jsvc - update to 9.0.100-8
tomcat-help - update to 9.0.100-8
tomcat10 (Debian package) - addressed in versions 10.1.52-1~deb12u1, 10.1.52-1~deb13u1
webMethods BPM - addressed in versions 10.15 Fix 14, 11.1 Fix 2
tomcat11 (Debian package) - update to 11.0.15-1~deb13u1
External References
Related Security Bulletins
- Session Fixation in Apache Tomcat
- Multiple vulnerabilities in IBM QRadar SIEM
- openEuler 24.03 LTS SP2 update for tomcat
- openEuler 24.03 LTS SP1 update for tomcat
- openEuler 22.03 LTS SP4 update for tomcat
- openEuler 22.03 LTS SP3 update for tomcat
- openEuler 20.03 LTS SP4 update for tomcat
- openEuler 24.03 LTS update for tomcat
- Multiple vulnerabilities in Cloudera Observability on Premises with IBM
- Multiple vulnerabilities in IBM Power HMC
- Multiple vulnerabilities in Netcool Operations Insight
- Debian update for tomcat10
- Debian update for tomcat11
- Multiple vulnerabilities in IBM webMethods BPM
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS and DOORS Web Access
- Multiple vulnerabilities in IBM Cloudera Data Platform Private Cloud Base with IBM (CDP)
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition