1 min read
BRICKSTORM APT Intrusion Campaign
Originally Published December 3, 2025
3 min read
Cyber Florida SOCAP Team
:
Updated on September 15, 2026
Originally Published May 13, 2025
Systems and applications using Apache Tomcat versions 11.0.0-M1 through 11.0.2, 10.1.0-M1 through 10.1.34, 9.0.0.M1 through 9.0.98.
CVE-2025-24813 describes a vulnerability in Apache Tomcat that would allow a malicious actor to perform a variety of attacks, such as remote code execution, information disclosure, and injecting malicious payloads or content into uploaded files. This type of vulnerability is caused by improper handling of path equivalence, which normally ensures that different file paths point to the same resource. This improper handling within the Default Servlet is related to write-enabled configurations in Apache Tomcat, and it impacts several versions of the application prior to the fix.
CVE-2025-24813 is a vulnerability affecting Apache Tomcat that can occur when the default servlet is configured to allow write functionality, which is normally disabled by default. This vulnerability can be exploited when combined with the default behavior of allowing for partial PUT requests. In this scenario, an attacker could upload a specially crafted serialized session file or simply a malicious payload to a writable directory within the system. Once the file is uploaded, a subsequent HTTP request triggers Tomcat to deserialize the file’s contents, executing the embedded malicious payload.
While exploiting CVE-2025-24813 can lead to a significant impact, successful remote code execution requires several prerequisites:
To mitigate attacks leveraging this vulnerability, these are the recommendations for CVE-2025-24813:
Upgrading Apache Tomcat to a Patched Version
By immediately upgrading to:
It provides a fix for the improper handling of partial PUT requests and path equivalency issues that could be exploited for remote code execution or file manipulation.
Configure Tomcat to disallow partial PUT requests, which allow clients to send file content in chunks or ranges. Recommended actions include:
This vulnerability exploits partial PUT behavior to inject content into files. If partial PUT is not supported, this attack vector is closed.
Ensure that the default servlet (the part of Tomcat that serves static files) cannot accept uploads or write to sensitive directories. To do so, you must:
If the default servlet has write permissions, attackers could upload or modify arbitrary files, which could lead to defacement, data theft, or execution of malicious scripts.
You should deploy or tune your WAF to:
Having a WAF can act as an additional protective layer by stopping attacks even if Tomcat is not yet patched or misconfigured.
Continuously monitor access logs (e.g., access_log, catalina.out) and security logs for:
Early detection of attempts allows you to respond quickly to intrusions before they escalate. Using tools such as Splunk, ELK stack, or Wazuh can make for efficient log review and analysis, with trigger alerts on anomalies.
| Type | Indicator |
|---|---|
| File System Anomalies | Presence of unexpected .jsp files in the web server root directory |
| Suspicious HTTP Requests | External POST or GET requests targeting suspicious .jsp files |
| Suspicious HTTP Methods | Occurrence of unexpected PUT requests in web server logs |
| Malicious Upload Attempts | Evidence of malicious payloads being delivered via PUT requests |
| WAF Detection | Triggered Web Application Firewall (WAF) rules indicating attempts to upload or execute unauthorized files |
Figure 1: Table of IOCs
Absholi7ly. (2025, March 22). POC-CVE-2025-24813: Proof of concept for CVE-2025-24813 in Apache Tomcat [Source code]. GitHub. https://github.com/absholi7ly/POC-CVE-2025-24813
Apache Software Foundation. (2025, March 10). CVE-2025-24813 Detail. National Vulnerability Database. https://nvd.nist.gov/vuln/detail/CVE-2025-24813
Detecting and mitigating Apache Tomcat CVE-2025-24813 | Akamai. Akamai Security Intelligence Group. (2025, March 25). https://www.akamai.com/blog/security-research/march-apache-tomcat-path-equivalence-traffic-detections-mitigations
Group, I. (2025, March 28). Apache Tomcat: CVE-2025-24813: Active exploitation. Recorded Future. https://www.recordedfuture.com/blog/apache-tomcat-cve-2025-24813-vulnerability-analysis
[SECURITY] CVE-2025-24813 Potential RCE and/or information disclosure and/or information corruption with partial PUT. Lists.apache.org. (2025, March 10). https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
Threat Advisory created by The Cyber Florida Security Operations Center.
Contributing Security Analysts: Jason Doan
1 min read
Originally Published December 3, 2025
1 min read
Published 04/13/2023 I. Targeted Entities Windows and Fortinet systems II. Introduction Several critical vulnerabilities were discovered in both...
1 min read
Originally published 10/19/2022