¡¾Îó²îͨ¸æ¡¿Apache TomcatÇå¾²Ô¼ÊøÈÆ¹ýÎó²î (CVE-2025-49125)
Ðû²¼Ê±¼ä 2025-06-17Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Apache TomcatÇå¾²Ô¼ÊøÈÆ¹ýÎó²î | ||
CVE ID | CVE-2025-49125 | ||
Îó²îÀàÐÍ | »á¼û¿ØÖÆÎó²î | ·¢Ã÷ʱ¼ä | 2025-06-17 |
Îó²îÆÀ·Ö | ÔÝÎÞ | Îó²îÆ·¼¶ | ¸ßΣ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
Apache TomcatÊÇÒ»¸ö¿ªÔ´µÄJava ServletÈÝÆ÷ºÍWebЧÀÍÆ÷£¬£¬Ö÷ÒªÓÃÓÚÔËÐÐJavaÓ¦ÓóÌÐò£¬£¬ÌØÊâÊÇ»ùÓÚServletºÍ"text-wrap-mode: wrap;">? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£¡£