By simply sending HTTP requests, attackers can trigger the deserialisation of malicious data in Tomcat's session storage and ...
A devastating new remote code execution (RCE) vulnerability, CVE-2025-24813, is now actively exploited in the wild. Attackers need just one PUT API request to take over vulnerable Apache Tomcat ...
Specifically, the attacker sends a PUT request containing a base64-encoded serialized Java payload saved to Tomcat's session storage. The attacker then sends a GET request with a JSESSIONID cookie ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results