Skip to main content

Threats Tagged 'cve-2025-31651'

View all threats tagged with 'cve-2025-31651'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-31651

Threats Tagged 'cve-2025-31651'

Click on any threat for detailed analysis and mitigation recommendations

This security advisory addresses vulnerabilities in the Public Key Infrastructure (PKI) Core packages required by the Red Hat Certificate System, specifically involving Apache Tomcat components. Two vulnerabilities are fixed: CVE-2025-31651, which allows bypass of rules in the Tomcat Rewrite Valve, and CVE-2025-55752, which involves directory traversal via rewrite with possible remote code execution. The update applies to Red Hat Enterprise Linux 8.6 variants including Advanced Mission Critical Update Support, Update Services for SAP Solutions, and Telecommunications Update Service. The advisory rates the security impact as Important. No CVSS scores are provided in the advisory. The vendor has released updated packages to address these issues.

Join the discussion

This security advisory from Red Hat addresses vulnerabilities in the Public Key Infrastructure (PKI) Core packages required by Red Hat Certificate System. It includes fixes for two Apache Tomcat vulnerabilities: a bypass of rules in the Rewrite Valve (CVE-2025-31651) and a directory traversal via rewrite with possible remote code execution (CVE-2025-55752). The update is rated as important by Red Hat Product Security and affects Red Hat Enterprise Linux 8.4 AUS and EUS extensions. No CVSS scores are provided in the advisory.

Join the discussion

This security advisory from Red Hat addresses vulnerabilities in the pki-deps:10.6 module used by Red Hat Enterprise Linux 8.2 AUS. It fixes two Apache Tomcat vulnerabilities: CVE-2025-31651, which allows bypass of rules in the Rewrite Valve, and CVE-2025-55752, which involves directory traversal via rewrite with possible remote code execution. The update is rated as having an Important security impact by Red Hat. No CVSS score is provided in the advisory. The vulnerabilities affect components fundamental to the Red Hat Certificate System.

Join the discussion

This advisory addresses two security vulnerabilities in Apache Tomcat used within Red Hat Enterprise Linux 9.2's pki-servlet-engine package. The first vulnerability (CVE-2025-31651) involves a bypass of rules in the Rewrite Valve component. The second (CVE-2025-55752) concerns a directory traversal vulnerability via rewrite rules that may lead to remote code execution. Red Hat has released an important security update to fix these issues in the pki-servlet-engine package version 9.0.50-1.el9_2.3. The update is available for multiple architectures and variants of Red Hat Enterprise Linux 9.2. No known exploits in the wild have been reported at this time.

Join the discussion

This advisory addresses two security vulnerabilities in Apache Tomcat used within Red Hat Enterprise Linux 9.0's pki-servlet-engine. The first vulnerability (CVE-2025-31651) involves a bypass of rules in the Rewrite Valve component. The second (CVE-2025-55752) is a directory traversal vulnerability via rewrite rules that may lead to remote code execution. Red Hat has released an update for the pki-servlet-engine package to remediate these issues. The update is rated as having an Important security impact. No CVSS scores are provided in the advisory.

Join the discussion
0

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) * tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) * tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) * tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) * tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Security Fix(es): * tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651) * tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Showing 1 to 10 of 20 results

Filters:Tag: cve-2025-31651
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses