Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Apache Tomcat and Camel Vulnerabilities Actively Exploited in The Wild

Posted on July 3, 2025July 3, 2025 By CWS

Essential vulnerabilities in Apache Tomcat and Apache Camel are being actively exploited by cybercriminals worldwide, with safety researchers documenting over 125,000 assault makes an attempt throughout greater than 70 nations since their disclosure in March 2025.

The three vulnerabilities—CVE-2025-24813 affecting Apache Tomcat and CVE-2025-27636 and CVE-2025-29891 impacting Apache Camel—allow distant code execution and pose vital dangers to organizations operating these widely-deployed Java-based platforms.

Apache Tomcat, the favored net server platform that permits Java-based net purposes, is susceptible by way of CVE-2025-24813, which impacts variations 9.0.0.M1 to 9.0.98, 10.1.0-M1 to 10.1.34, and 11.0.0-M1 to 11.0.2.

The flaw exploits Tomcat’s partial PUT performance mixed with session persistence options, permitting attackers to govern serialized session information and obtain arbitrary code execution.

Apache Camel, an integration framework for connecting various techniques, suffers from two associated vulnerabilities that allow attackers to bypass header filtering mechanisms by way of case-sensitive manipulation strategies.

Two steps of the exploit (Supply – Palo Alto Networks)

Palo Alto Networks researchers recognized a dramatic surge in exploitation makes an attempt instantly following the vulnerabilities’ public disclosure, with assault frequency peaking inside the first week of March 2025.

The safety agency’s telemetry techniques blocked 125,856 probes, scans, and exploit makes an attempt, together with 7,859 particularly concentrating on the Tomcat vulnerability.

Evaluation of the assault patterns reveals each automated scanning instruments and lively exploitation makes an attempt, with many assaults using the freely out there Nuclei Scanner framework.

The risk panorama has developed quickly because the preliminary disclosures, with proof-of-concept exploits changing into publicly out there shortly after Apache launched safety patches.

Cached session file (Supply – Palo Alto Networks)

The benefit of exploitation has lowered the barrier for much less subtle risk actors, making these vulnerabilities significantly harmful for organizations that haven’t utilized vital updates.

Tomcat’s Partial PUT Exploitation Mechanism

The CVE-2025-24813 vulnerability leverages a classy two-step assault course of that exploits Tomcat’s dealing with of partial PUT requests with Content material-Vary headers.

Attackers first stage their malicious payload by sending an HTTP PUT request containing serialized malicious code, with the filename ending in “.session” to make sure correct caching by Tomcat’s session persistence mechanism.

The preliminary payload deployment requires particular server configurations, together with a disabled readonly parameter and enabled session persistence.

When these situations are met, Tomcat saves the attacker’s serialized code to 2 places: a traditional cache file beneath the webapps listing and a brief file with a number one interval within the work listing.

The exploitation course of concludes when the attacker sends a follow-up HTTP GET request containing a rigorously crafted JSESSIONID cookie worth that triggers deserialization of the cached malicious code.

Examine stay malware conduct, hint each step of an assault, and make sooner, smarter safety choices -> Attempt ANY.RUN now

Cyber Security News Tags:Actively, Apache, Camel, Exploited, Tomcat, Vulnerabilities, Wild

Post navigation

Previous Post: Massive Android Fraud Operations Uncovered: IconAds, Kaleidoscope, SMS Malware, NFC Scams
Next Post: Citrix Warns Authentication Failures Following The Update of NetScaler to Fix Auth Vulnerability

Related Posts

1000+ Exposed N-able N-central RMM Servers Unpatched for 0-Day Vulnerabilities Cyber Security News
Threat Actors Impersonate Fake Docusign Notifications To Steal Corporate Data Cyber Security News
Cloudflare Confirms Recent 1.1.1.1 DNS Outage Caused by BGP Attack or Hijack Cyber Security News
Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats Cyber Security News
Hackers Upload Weaponized Packages to PyPI Repositories to Steal AWS, CI/CD and macOS Data Cyber Security News
How Smart Timesheet Software Is Changing the Way of Work Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Slow and Steady Security: Lessons from the Tortoise and the Hare
  • Lenovo AI Chatbot Vulnerability Let Attackers Run Remote Scripts on Corporate Machines
  • Microsoft Office.com Suffers Major Outage, Investigation Underway
  • Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts
  • RapperBot Botnet Disrupted, American Administrator Indicted

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Slow and Steady Security: Lessons from the Tortoise and the Hare
  • Lenovo AI Chatbot Vulnerability Let Attackers Run Remote Scripts on Corporate Machines
  • Microsoft Office.com Suffers Major Outage, Investigation Underway
  • Experts Find AI Browsers Can Be Tricked by PromptFix Exploit to Run Malicious Hidden Prompts
  • RapperBot Botnet Disrupted, American Administrator Indicted

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News