CVE-2025-49124

NameCVE-2025-49124
DescriptionUntrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat10 (PTS)bookworm, bookworm (security)10.1.34-0+deb12u2fixed
sid, trixie10.1.40-1fixed
tomcat11 (PTS)sid, trixie11.0.6-1fixed
tomcat9 (PTS)bullseye9.0.43-2~deb11u10fixed
bullseye (security)9.0.43-2~deb11u12fixed
bookworm9.0.70-2fixed
sid, trixie9.0.95-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat10source(unstable)(not affected)
tomcat11source(unstable)(not affected)
tomcat9source(unstable)(not affected)

Notes

- tomcat11 <not-affected> (Windows-specific)
- tomcat10 <not-affected> (Windows-specific)
- tomcat9 <not-affected> (Windows-specific)
https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv

Search for package or bug name: Reporting problems