CVE-2025-48989

Public on 2025-08-13
Modified on 2025-08-26
Description
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.

Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Tomcat9 Extra tomcat 2025-09-04 ALAS2TOMCAT9-2025-022 Fixed
Amazon Linux 2 - Core tomcat Not Affected
Amazon Linux 2023 tomcat10 2025-09-08 ALAS2023-2025-1166 Fixed
Amazon Linux 1 tomcat7 No Fix Planned
Amazon Linux 1 tomcat8 No Fix Planned
Amazon Linux 1 tomcat80 No Fix Planned
Amazon Linux 2023 tomcat9 2025-09-08 ALAS2023-2025-1167 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H