Security Bulletin: Vulnerability in Apache Tomcat Server (CVE-2025-24813) affects Power HMC.

Vulnerability Details

Basic Information

Title Security Bulletin: Vulnerability in Apache Tomcat Server (CVE-2025-24813) affects Power HMC.
Type ibm
Published 2025-04-22T10:28:32
Last Seen 2025-04-22T10:56:21
CVSS Score 9.8 (CRITICAL)

CVSS v3 Details

Attack Vector NETWORK
Attack Complexity LOW
Privileges Required NONE
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-24813
CWE
Bulletin Family software

Description

## Summary

The Apache Tomcat Server is used by Power Hardware Management Console (HMC). HMC has addressed the applicable CVE.

## Vulnerability Details

**CVEID:**CVE-2025-24813
**DESCRIPTION:** Path Equivalence: ‘file.Name’ (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files: \- writes enabled for the default servlet (disabled by default) \- support for partial PUT (enabled by default) \- a target URL for security sensitive uploads that was a sub-directory of a target URL for public uploads \- attacker knowledge of the names of security sensitive files being uploaded \- the security sensitive files also being uploaded via partial PUT If all of the following were true, a malicious user was able to perform remote code execution: \- writes enabled for the default servlet (disabled by default) \- support for partial PUT (enabled by default) \- application was using Tomcat’s file based session persistence with the default storage location \- application included a library that may be leveraged in a deserialization attack Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.
**CWE:**CWE-44: Path Equivalence: ‘file.name’ (Internal Dot)
**CVSS Source:** NVD
**CVSS Base score:** 9.8
**CVSS Vector:**(CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)

## Affected Products and Versions

Affected Product(s)| Version(s)
—|—
HMC V10.2.1030.0| V10.2.1030.0
HMC V10.3.1050.0| V10.3.1050.0

## Remediation/Fixes

The following fixes are available on IBM Fix Central at: http://www-933.ibm.com/support/fixcentral/

Product | VRMF | APAR | Remediation/Fix
—|—|—|—
Power HMC | V10.2.1040.0 SP3 x86 | MB04482 | MF71717
Power HMC | V10.2.1040.0 SP3 ppc | MB04483 | MF71718
Power HMC | V10.3.1060.0 SP1 x86 | MB04484 | MF71719
Power HMC | V10.3.1060.0 SP1 ppc | MB04485 | MF71720

## Workarounds and Mitigations

None

##

Impact Assessment

Base Score 9.8
Severity CRITICAL

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.