Threats Tagged 'cve-2025-46701'
View all threats tagged with 'cve-2025-46701'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-46701'
Click on any threat for detailed analysis and mitigation recommendations
0 This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 9. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 9 versions are advised to apply the update as detailed in the Red Hat advisory. Join the discussion | GCVE Database | 05/19/2026, 13:41:35 UTC Added: 05/28/2026, 22:15:03 UTC |
0 This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 10. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 10 versions should apply the provided updates to mitigate these issues. Join the discussion | GCVE Database | 05/19/2026, 09:22:51 UTC Added: 05/28/2026, 22:15:03 UTC |
0 Red Hat has issued a security advisory for tomcat9 in Red Hat Enterprise Linux 10 addressing three vulnerabilities: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). These vulnerabilities affect the Apache Tomcat servlet container used for Java Servlet and JavaServer Pages technologies. The update is rated as important by Red Hat Product Security and applies to tomcat9 packages in RHEL 10. A security update is available to remediate these issues. Join the discussion | GCVE Database | 05/19/2026, 09:00:26 UTC Added: 05/28/2026, 22:15:03 UTC |
Red Hat JBoss Web Server 6.2.0 includes security fixes addressing three vulnerabilities in Apache Tomcat components: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). This release replaces version 6.1.3 and is rated with moderate severity by Red Hat Product Security. The update is available for Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory. Join the discussion | GCVE Database | 02/16/2026, 18:57:53 UTC Added: 05/28/2026, 22:15:03 UTC |
Red Hat JBoss Web Server 6.2.0 addresses multiple security vulnerabilities present in versions from 6.1.3 up to but not including 6.2.0. The fixed issues include a security constraint bypass for CGI scripts, session fixation via the rewrite valve, and console manipulation in Apache Tomcat components. These vulnerabilities have been rated with moderate severity by Red Hat. The update replaces version 6.1.3 and includes bug fixes and component upgrades. Users are advised to back up their installations before applying the update. Join the discussion | GCVE Database | 02/16/2026, 18:55:18 UTC Added: 05/28/2026, 22:15:03 UTC |
CVE-2025-46701 is a security vulnerability in Apache Tomcat affecting multiple versions from 6.0.37 through 11.0.6. It involves improper handling of case sensitivity in the CGI servlet, allowing bypass of security constraints applied to the pathInfo component of a URI. This flaw could enable an attacker to bypass authentication mechanisms. The issue has been fixed in Apache Tomcat versions 11.0.7, 10.1.41, and 9.0.105. Users are advised to upgrade to these or later versions to mitigate the risk. Join the discussion | GCVE Database | 07/10/2025, 10:47:00 UTC Added: 07/16/2026, 10:40:07 UTC |
0 Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. Join the discussion | CVE Database V5 | 05/29/2025, 19:06:04 UTC Added: 05/29/2025, 19:14:08 UTC |
Showing 1 to 7 of 7 results