Skip to main content

Threats Tagged 'cve-2025-55668'

View all threats tagged with 'cve-2025-55668'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-55668

Threats Tagged 'cve-2025-55668'

Click on any threat for detailed analysis and mitigation recommendations

0

This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 9. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 9 versions are advised to apply the update as detailed in the Red Hat advisory.

Join the discussion
0

This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 10. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 10 versions should apply the provided updates to mitigate these issues.

Join the discussion
0

Red Hat has issued a security advisory for tomcat9 in Red Hat Enterprise Linux 10 addressing three vulnerabilities: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). These vulnerabilities affect the Apache Tomcat servlet container used for Java Servlet and JavaServer Pages technologies. The update is rated as important by Red Hat Product Security and applies to tomcat9 packages in RHEL 10. A security update is available to remediate these issues.

Join the discussion

This update includes the following RPMs: tomcat10: * tomcat10-10.1.54-1.hum1 (noarch) * tomcat10-admin-webapps-10.1.54-1.hum1 (noarch) * tomcat10-common-10.1.54-1.hum1 (noarch) * tomcat10-docs-webapp-10.1.54-1.hum1 (noarch) * tomcat10-el-5.0-api-10.1.54-1.hum1 (noarch) * tomcat10-jsp-3.1-api-10.1.54-1.hum1 (noarch) * tomcat10-lib-10.1.54-1.hum1 (noarch) * tomcat10-servlet-6.0-api-10.1.54-1.hum1 (noarch) * tomcat10-user-instance-10.1.54-1.hum1 (noarch) * tomcat10-webapps-10.1.54-1.hum1 (noarch) * tomcat10-10.1.54-1.hum1.src (src)

Join the discussion

This update includes the following RPMs: tomcat11: * tomcat11-11.0.21-0.1.hum1 (noarch) * tomcat11-admin-webapps-11.0.21-0.1.hum1 (noarch) * tomcat11-docs-webapp-11.0.21-0.1.hum1 (noarch) * tomcat11-el-6.0-api-11.0.21-0.1.hum1 (noarch) * tomcat11-jsp-4.0-api-11.0.21-0.1.hum1 (noarch) * tomcat11-lib-11.0.21-0.1.hum1 (noarch) * tomcat11-servlet-6.1-api-11.0.21-0.1.hum1 (noarch) * tomcat11-webapps-11.0.21-0.1.hum1 (noarch) * tomcat11-11.0.21-0.1.hum1.src (source)

Join the discussion

Red Hat JBoss Web Server 6.2.0 includes security fixes addressing three vulnerabilities in Apache Tomcat components: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). This release replaces version 6.1.3 and is rated with moderate severity by Red Hat Product Security. The update is available for Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory.

Join the discussion

Red Hat JBoss Web Server 6.2.0 addresses multiple security vulnerabilities present in versions from 6.1.3 up to but not including 6.2.0. The fixed issues include a security constraint bypass for CGI scripts, session fixation via the rewrite valve, and console manipulation in Apache Tomcat components. These vulnerabilities have been rated with moderate severity by Red Hat. The update replaces version 6.1.3 and includes bug fixes and component upgrades. Users are advised to back up their installations before applying the update.

Join the discussion

A session fixation vulnerability exists in Apache Tomcat via the rewrite valve. This affects Apache Tomcat versions from 11.0.0 through 11.0.7, 10.1.0 through 10.1.41, and 9.0.0 through 9.0.105, with older end-of-life versions potentially also affected. The issue allows an attacker to fixate a session identifier, potentially leading to unauthorized session access. Fixed versions are 11.0.8, 10.1.42, and 9.0.106.

Join the discussion

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Tag: cve-2025-55668
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses