Metrics
Affected Vendors & Products
Thu, 07 Aug 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. |
Wed, 25 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache tomcat |
|
CPEs | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache tomcat |
Tue, 10 Jun 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
threat_severity
|
threat_severity
|
Sat, 07 Jun 2025 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
threat_severity
|
threat_severity
|
Sat, 31 May 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Fri, 30 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 29 May 2025 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 29 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104. Users are recommended to upgrade to version 11.0.7, 10.1.41 or 9.0.105, which fixes the issue. | |
Title | Apache Tomcat: Security constraint bypass for CGI scripts | |
Weaknesses | CWE-178 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-05-29T19:06:04.289Z
Updated: 2025-08-07T11:32:27.148Z
Reserved: 2025-04-28T12:28:07.568Z
Link: CVE-2025-46701

Updated: 2025-05-29T22:03:08.967Z

Status : Modified
Published: 2025-05-29T19:15:27.983
Modified: 2025-08-07T12:15:30.177
Link: CVE-2025-46701
