Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache tomcat |
|
CPEs | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache tomcat |
Tue, 17 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 16 Jun 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Mon, 16 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue. | |
Title | Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows | |
Weaknesses | CWE-426 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-06-16T14:22:16.288Z
Updated: 2025-06-17T14:05:52.571Z
Reserved: 2025-06-02T08:34:46.719Z
Link: CVE-2025-49124

Updated: 2025-06-16T20:03:24.388Z

Status : Analyzed
Published: 2025-06-16T15:15:24.707
Modified: 2025-07-02T18:28:47.897
Link: CVE-2025-49124

No data.