Apache Tomcat, Relative Path Traversal, CVE-2025-45231 (High)

Listen to this Post

The vulnerability stems from a regression introduced by the fix for bug 60013. The flawed code normalized the URL before URL decoding, creating a logic error in the request processing pipeline. For configurations using RewriteRule directives that map query parameters into the URL path, an attacker can craft a malicious request with encoded path traversal sequences (e.g., `%2e%2e%2f` for ../). Because normalization, which resolves ../, occurs on the still-encoded URL, these sequences are not correctly interpreted. Subsequent URL decoding then reveals the traversal sequence, allowing access to restricted directories like `/WEB-INF/` or /META-INF/. If the HTTP PUT method is enabled, this flaw can be leveraged to upload a malicious JSP file directly into a web-accessible directory, ultimately leading to Remote Code Execution.
Platform: Apache Tomcat
Version: 8.5.60-100, 9.0.40-108
Vulnerability: Path Traversal
Severity: High
date: 2025-10-27

Prediction: 2025-11-10

What Undercode Say:

curl -X PUT 'http://target:8080/app/..%2fWEB-INF/web.xml' -d @malicious_file.jsp
<Valve className="org.apache.catalina.valves.rewrite.RewriteValve" />
// Flawed logic: normalize -> decode
String normalized = RequestUtil.normalize(encodedURI);
String decoded = URLDecoder.decode(normalized, "UTF-8");

How Exploit:

Craft requests with encoded `../` sequences in parameters mapped by RewriteRule to bypass security constraints and access/WEB-INF. If PUT is enabled, upload a JSP webshell for RCE.

Protection from this CVE

Upgrade to Tomcat 11.0.11+, 10.1.45+, or 9.0.109+. Disable PUT method if unused. Review and audit all RewriteRule configurations.

Impact:

Information Disclosure. Remote Code Execution.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top