Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
History

Wed, 02 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
CPEs cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache tomcat

Tue, 17 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
Description Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Title Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows
Weaknesses CWE-426
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-06-16T14:22:16.288Z

Updated: 2025-06-17T14:05:52.571Z

Reserved: 2025-06-02T08:34:46.719Z

Link: CVE-2025-49124

cve-icon Vulnrichment

Updated: 2025-06-16T20:03:24.388Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-16T15:15:24.707

Modified: 2025-07-02T18:28:47.897

Link: CVE-2025-49124

cve-icon Redhat

No data.