{"id":"UBUNTU-CVE-2025-49124","details":"Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100 and 7.0.95 through 7.0.109. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.","modified":"2025-08-20T05:00:23Z","published":"2025-06-16T15:15:00Z","withdrawn":"2025-08-21T16:57:29Z","upstream":["CVE-2025-49124"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-49124"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-49124"},{"type":"REPORT","url":"https://lists.apache.org/thread/lnow7tt2j6hb9kcpkggx32ht6o90vqzv"},{"type":"REPORT","url":"http://www.openwall.com/lists/oss-security/2025/06/16/3"}],"affected":[{"package":{"name":"tomcat9","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2+esm7?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.16-3~18.04.1","9.0.16-3ubuntu0.18.04.1","9.0.16-3ubuntu0.18.04.2","9.0.16-3ubuntu0.18.04.2+esm1","9.0.16-3ubuntu0.18.04.2+esm2","9.0.16-3ubuntu0.18.04.2+esm3","9.0.16-3ubuntu0.18.04.2+esm4","9.0.16-3ubuntu0.18.04.2+esm5","9.0.16-3ubuntu0.18.04.2+esm6","9.0.16-3ubuntu0.18.04.2+esm7"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat9","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.9+esm2?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.24-1","9.0.27-1","9.0.31-1","9.0.31-1ubuntu0.1","9.0.31-1ubuntu0.2","9.0.31-1ubuntu0.3","9.0.31-1ubuntu0.4","9.0.31-1ubuntu0.5","9.0.31-1ubuntu0.6","9.0.31-1ubuntu0.7","9.0.31-1ubuntu0.8","9.0.31-1ubuntu0.9","9.0.31-1ubuntu0.9+esm1","9.0.31-1ubuntu0.9+esm2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat9","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.43-3","9.0.54-1","9.0.55-1","9.0.58-1","9.0.58-1ubuntu0.1","9.0.58-1ubuntu0.2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat10","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tomcat10@10.1.16-1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.1.10-1","10.1.14-1","10.1.15-1","10.1.16-1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat9","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu0.1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.70-1ubuntu1","9.0.70-2","9.0.70-2ubuntu0.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat10","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/tomcat10@10.1.35-1ubuntu0.1?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.1.25-1","10.1.31-1","10.1.33-1","10.1.34-1","10.1.35-1","10.1.35-1ubuntu0.1"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}},{"package":{"name":"tomcat9","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu1.25.04.2?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.0.70-2ubuntu1.1","9.0.70-2ubuntu1.25.04.1","9.0.70-2ubuntu1.25.04.2"],"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-49124.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}