vulnerability

Red Hat: CVE-2025-55752: tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (Multiple Advisories)

Severity
9
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:C)
Published
Oct 27, 2025
Added
Dec 11, 2025
Modified
Jan 28, 2026

Description

A directory traversal vulnerability in Apache Tomcat caused by improper URL normalization during request rewriting. When specific rewrite rules are used, an attacker could craft a malicious request to bypass access restrictions and reach protected directories such as /WEB-INF/ or /META-INF/. If HTTP PUT requests are also enabled, this flaw could allow the upload of malicious files, potentially leading to remote code execution.

Solutions

redhat-upgrade-tomcatredhat-upgrade-tomcat-admin-webappsredhat-upgrade-tomcat-docs-webappredhat-upgrade-tomcat-el-3-0-apiredhat-upgrade-tomcat-el-5-0-apiredhat-upgrade-tomcat-jsp-2-3-apiredhat-upgrade-tomcat-jsp-3-1-apiredhat-upgrade-tomcat-libredhat-upgrade-tomcat-servlet-4-0-apiredhat-upgrade-tomcat-servlet-6-0-apiredhat-upgrade-tomcat-webappsredhat-upgrade-tomcat9redhat-upgrade-tomcat9-admin-webappsredhat-upgrade-tomcat9-docs-webappredhat-upgrade-tomcat9-el-3-0-apiredhat-upgrade-tomcat9-jsp-2-3-apiredhat-upgrade-tomcat9-libredhat-upgrade-tomcat9-servlet-4-0-apiredhat-upgrade-tomcat9-webapps
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.