A security scan has identified vulnerability CVE-2025-24813 for the Apache Tomcat version used by Foglight.
Is Foglight affected by the Apache Tomcat Vulnerability CVE-2025-24813 for Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet?
The vulnerability is fixed in Apache Tomcat 9.0.99.
The vulnerability requires a non-default configuration where write access is enabled on the Apache Tomcat default servlet.
Foglight is not affected as it uses the default configuration with the servlet in read-only mode.
© 2025 Quest Software Inc. ALL RIGHTS RESERVED. Conditions d’utilisation Confidentialité Cookie Preference Center