Threats Tagged 'cve-2025-55754'
View all threats tagged with 'cve-2025-55754'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-55754'
Click on any threat for detailed analysis and mitigation recommendations
0 This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 9. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 9 versions are advised to apply the update as detailed in the Red Hat advisory. Join the discussion | GCVE Database | 05/19/2026, 13:41:35 UTC Added: 05/28/2026, 22:15:03 UTC |
0 This advisory addresses multiple security vulnerabilities in Apache Tomcat as packaged for Red Hat Enterprise Linux 10. The issues include a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). Red Hat has released updated Tomcat packages to fix these vulnerabilities. The update is rated as having an Important security impact by Red Hat Product Security. Users of affected Red Hat Enterprise Linux 10 versions should apply the provided updates to mitigate these issues. Join the discussion | GCVE Database | 05/19/2026, 09:22:51 UTC Added: 05/28/2026, 22:15:03 UTC |
0 Red Hat has issued a security advisory for tomcat9 in Red Hat Enterprise Linux 10 addressing three vulnerabilities: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). These vulnerabilities affect the Apache Tomcat servlet container used for Java Servlet and JavaServer Pages technologies. The update is rated as important by Red Hat Product Security and applies to tomcat9 packages in RHEL 10. A security update is available to remediate these issues. Join the discussion | GCVE Database | 05/19/2026, 09:00:26 UTC Added: 05/28/2026, 22:15:03 UTC |
0 This update includes the following RPMs: tomcat10: * tomcat10-10.1.54-1.hum1 (noarch) * tomcat10-admin-webapps-10.1.54-1.hum1 (noarch) * tomcat10-common-10.1.54-1.hum1 (noarch) * tomcat10-docs-webapp-10.1.54-1.hum1 (noarch) * tomcat10-el-5.0-api-10.1.54-1.hum1 (noarch) * tomcat10-jsp-3.1-api-10.1.54-1.hum1 (noarch) * tomcat10-lib-10.1.54-1.hum1 (noarch) * tomcat10-servlet-6.0-api-10.1.54-1.hum1 (noarch) * tomcat10-user-instance-10.1.54-1.hum1 (noarch) * tomcat10-webapps-10.1.54-1.hum1 (noarch) * tomcat10-10.1.54-1.hum1.src (src) Join the discussion | GCVE Database | 04/15/2026, 17:31:38 UTC Added: 06/10/2026, 11:41:37 UTC |
0 This update includes the following RPMs: tomcat11: * tomcat11-11.0.21-0.1.hum1 (noarch) * tomcat11-admin-webapps-11.0.21-0.1.hum1 (noarch) * tomcat11-docs-webapp-11.0.21-0.1.hum1 (noarch) * tomcat11-el-6.0-api-11.0.21-0.1.hum1 (noarch) * tomcat11-jsp-4.0-api-11.0.21-0.1.hum1 (noarch) * tomcat11-lib-11.0.21-0.1.hum1 (noarch) * tomcat11-servlet-6.1-api-11.0.21-0.1.hum1 (noarch) * tomcat11-webapps-11.0.21-0.1.hum1 (noarch) * tomcat11-11.0.21-0.1.hum1.src (source) Join the discussion | GCVE Database | 04/04/2026, 16:29:57 UTC Added: 06/10/2026, 11:41:37 UTC |
Red Hat JBoss Web Server 6.2.0 includes security fixes addressing three vulnerabilities in Apache Tomcat components: a security constraint bypass for CGI scripts (CVE-2025-46701), session fixation via the rewrite valve (CVE-2025-55668), and console manipulation (CVE-2025-55754). This release replaces version 6.1.3 and is rated with moderate severity by Red Hat Product Security. The update is available for Red Hat Enterprise Linux 8, 9, and 10. No CVSS scores are provided in the advisory. Join the discussion | GCVE Database | 02/16/2026, 18:57:53 UTC Added: 05/28/2026, 22:15:03 UTC |
Red Hat JBoss Web Server 6.2.0 addresses multiple security vulnerabilities present in versions from 6.1.3 up to but not including 6.2.0. The fixed issues include a security constraint bypass for CGI scripts, session fixation via the rewrite valve, and console manipulation in Apache Tomcat components. These vulnerabilities have been rated with moderate severity by Red Hat. The update replaces version 6.1.3 and includes bug fixes and component upgrades. Users are advised to back up their installations before applying the update. Join the discussion | GCVE Database | 02/16/2026, 18:55:18 UTC Added: 05/28/2026, 22:15:03 UTC |
0 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue. Join the discussion | CVE Database V5 | 11/06/2025, 13:00:33 UTC Added: 10/27/2025, 17:37:46 UTC |
Showing 1 to 8 of 8 results