CVE-2025-49124

NameCVE-2025-49124
DescriptionUntrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat10 (PTS)bookworm, bookworm (security)10.1.34-0+deb12u2fixed
trixie10.1.40-1fixed
forky, sid10.1.46-1fixed
tomcat11 (PTS)trixie11.0.6-1fixed
forky, sid11.0.11-1fixed
tomcat9 (PTS)bullseye9.0.43-2~deb11u10fixed
bullseye (security)9.0.107-0+deb11u1fixed
bookworm9.0.70-2fixed
trixie9.0.95-1fixed
forky, sid9.0.111-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat10source(unstable)(not affected)
tomcat11source(unstable)(not affected)
tomcat9source(unstable)(not affected)

Notes

- tomcat11 <not-affected> (Windows-specific)
- tomcat10 <not-affected> (Windows-specific)
- tomcat9 <not-affected> (Windows-specific)
https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv

Search for package or bug name: Reporting problems