CVE-2025-55668
MEDIUM 6.5EPSS 0.8%
Session Fixation vulnerability in Apache Tomcat via rewrite valve.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.Older, EOL versions may also be affected.Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS
- 0.83% chance of exploitation in the next 30 days, 55th percentile
- Published
- 2025-08-13
- Updated
- 2025-11-04
Proof-of-concept exploits (1)
- gregk4sec/CVE-2025-556680★ · 2025-08-13