Tech

A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease

Share
Share


  • Security outfit Wallarm spotted a PoC in the wild
  • The method abuses a deserialization flaw in Apache Tomcat
  • It allows attackers to fully take over vulnerable endpoints

A deserialization vulnerability on Apache Tomcat servers is being abused in the wild to completely take over affected endpoints, security researchers are warning.

Wallarm has revealed it saw a Chinese forum user, alias iSee857, share a proof-of-concept (PoC) for a flaw tracked as CVE-2025-24813, warning threat actors only need one PUT API request to take over the vulnerable server. The request is used to upload a malicious serialized Java session, which then allows the attacker to trigger deserialization by referencing the malicious session ID in a GET request.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
AI took a huge leap in IQ, and now a quarter of Gen Z thinks AI is conscious
Tech

AI took a huge leap in IQ, and now a quarter of Gen Z thinks AI is conscious

ChatGPT’s o3 model scored a 136 on the Mensa IQ test and...

DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider
Tech

DeepSeek sees surge in developer use as 3 in 10 businesses adopt the controversial LLM provider

Developers shift from loyalty to flexibility as OpenAI leads, but DeepSeek gains...

China’s CATL launches new EV sodium battery
Tech

China’s CATL launches new EV sodium battery

Chinese battery giant CATL has launched a new sodium-ion battery it says...