elsa-2025-23052
oracle_linux
Description
[1:9.0.87-8.1] - Resolves: RHEL-124497 tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752) - Resolves: RHEL-91732 tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2025-31651",
"CVE-2025-55752"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1:9.0.87-8.1]\n- Resolves: RHEL-124497\n tomcat: Directory traversal via rewrite with possible RCE (CVE-2025-55752)\n- Resolves: RHEL-91732\n tomcat: Bypass of rules in Rewrite Valve (CVE-2025-31651)",
"id": "ELSA-2025-23052",
"ovalId": "oval:com.oracle.elsa:def:202523052",
"source": "oracle_linux",
"title": "ELSA-2025-23052: tomcat9 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2025-23052.html"
}