Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-49124

Опубликовано: 16 июн. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.4

Описание

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

РелизСтатусПримечание
devel

not-affected

Windows-specific
esm-apps/noble

not-affected

Windows-specific
jammy

DNE

noble

not-affected

Windows-specific
oracular

ignored

end of life, was needs-triage
plucky

not-affected

Windows-specific
upstream

not-affected

debian: Windows-specific

Показывать по

РелизСтатусПримечание
devel

not-affected

Windows-specific
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

not-affected

debian: Windows-specific

Показывать по

РелизСтатусПримечание
devel

not-affected

Windows-specific
esm-apps/bionic

not-affected

Windows-specific
esm-apps/focal

not-affected

Windows-specific
esm-apps/jammy

not-affected

Windows-specific
esm-apps/noble

not-affected

Windows-specific
jammy

not-affected

Windows-specific
noble

not-affected

Windows-specific
oracular

ignored

end of life, was needs-triage
plucky

not-affected

Windows-specific
upstream

not-affected

debian: Windows-specific

Показывать по

EPSS

Процентиль: 3%
0.00015
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
8 месяцев назад

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

CVSS3: 8.4
debian
8 месяцев назад

Untrusted Search Path vulnerability in Apache Tomcat installer for Win ...

github
8 месяцев назад

Apache Tomcat installer for Windows has an untrusted search path vulnerability

CVSS3: 8.4
fstec
8 месяцев назад

Уязвимость программного обеспечения Apache Tomcat, связанная с использованием ненадёжного пути поиска, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 3%
0.00015
Низкий

8.4 High

CVSS3