CVE-2025-55668

Published Aug 13, 2025

Last updated 7 months ago

Overview

Description
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Source
security@apache.org
NVD status
Analyzed
Products
tomcat

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-384

Social media

Hype score
Not currently trending
  1. [JVNVU#95006047] Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/9wL3zQaj9H #jvn #脆弱性 #セキュリティ

    @jpsecuritynews

    20 Aug 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 統合版 JPCERT/CC | JVN: Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/8jLCS3JziG #itsec_jp

    @itsec_jp

    20 Aug 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. JVNVU#95006047 Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/qWnqt1P2BY

    @Syynya

    19 Aug 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. JVNVU#95006047: Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/sWn99W89EC

    @ohhara_shiojiri

    19 Aug 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Apache Software FoundationがApache Tomcatの脆弱性を解決するアップデートを出したという話。 Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) The Apache Software Foundationから、Apache Tomcatの脆弱

    @stem4jp

    19 Aug 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. #後で読む 用メモです→ Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/WTP02DDW5I

    @TommiyTw

    19 Aug 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. JVNとかでTomcatの脆弱性として挙げられてますがRHELの影響を受けるパッケージはlog4jとかになってますね... Moderate:6.5 // "CVE-2025-55668" https://t.co/zINr6t7DqA

    @w4yh

    19 Aug 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/G97fPwVRZf #%E6%8A%80%E8%A1%93%E7%B3%BB-%20%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3 #feedly

    @likecoffee

    19 Aug 2025

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [2025/08/19 10:15 公表] Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668) https://t.co/EGY2cUCrP4

    @jvnjp

    19 Aug 2025

    2216 Impressions

    2 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  10. CVE-2025-48989: Apache Tomcat: h2 DoS - Made You Reset https://t.co/7pxUUQWawG CVE-2025-55668: Apache Tomcat: session fixation via rewrite valve https://t.co/q97wWQLI3v

    @oss_security

    13 Aug 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.