• CVE-2025-46701

发布时间: 2025年6月13日

修改时间: 2025年6月13日

概要

A vulnerability was found in Apache Tomcat up to 9.0.104/10.1.40/11.0.6 (Application Server Software) and classified as critical.Using CWE to declare the problem leads to CWE-178. The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.Impacted is integrity.Upgrading to version 9.0.105, 10.1.41 or 11.0.7 eliminates this vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Network
CVSS评分 N/A 7.3
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity Low
User Interaction None
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2681 tomcat security update 2025年6月20日

影响产品

产品 状态
V6 tomcat Fixed
KY3.4-5A tomcat Fixed
KY3.5.3 tomcat Fixed
KY3.5.2 tomcat Fixed