#VU117681 Path traversal in Apache Tomcat - CVE-2025-55752
Published: October 27, 2025 / Updated: October 31, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences passed via Rewrite Valve. A remote attacker can send a specially crafted HTTP PUT request and write arbitrary files to the server, leading to remote code execution.