Is Data Center Security (DCS) affected by CVE-2025-24813 vulnerability?
search cancel

Is Data Center Security (DCS) affected by CVE-2025-24813 vulnerability?

book

Article ID: 391714

calendar_today

Updated On: 03-24-2025

Products

Data Center Security Monitoring Edition Data Center Security Server Data Center Security Server Advanced

Issue/Introduction

You received a security advisory regarding the following critical vulnerability:
 
CVE-2025-24813 - Apache Tomcat Path Traversal & Remote Code Execution (RCE).

You would like to know if Data Center Security (DCS) is affected by this vulnerability.

Environment

DCS 6.9.x

Cause

CVE-2025-24813 is a critical Remote Code Execution (RCE) vulnerability affecting Apache Tomcat. The flaw originates from a path equivalence issue in the server’s request-handling mechanism, allowing attackers to bypass security constraints and execute arbitrary code remotely.

By crafting specially designed HTTP requests, attackers can gain unauthorized access to restricted resources, manipulate server configurations, and execute malicious commands. This vulnerability is particularly dangerous due to Apache Tomcat’s widespread use in enterprise environments, where successful exploitation could lead to privilege escalation, data exfiltration, and lateral movement across networks.

Resolution

DCS is not affected, please refer to our official: Enterprise Security Group Advisory for CVE-2025-24813

Additional Information