← All articles Best Practices

CVE-2025-30066: Apache Tomcat RCE Exploit Chain Analysis for Defenders

By Ammar Khan, CEH · June 30, 2026 · CybernytronX Research
CVE-2025-30066: Apache Tomcat RCE Exploit Chain Analysis for Defenders

On March 10, 2025, the Apache Software Foundation released a security advisory for CVE-2025-30066, a critical remote code execution vulnerability in Apache Tomcat's session persistence mechanism. The flaw, carrying a CVSS v3.1 score of 9.8, allows unauthenticated attackers to deserialize malicious Java objects stored in session files, leading to full server compromise. This exploit chain bypasses typical deserialization protections by leveraging Tomcat's built-in PersistenceManager component. After reading this analysis, SOC analysts and security engineers will understand the exact attack vectors, be able to deploy Sigma and YARA detection rules, and apply vendor-recommended mitigations.

1. Background: The Vulnerability and Its Root Cause

CVE-2025-30066 affects Apache Tomcat versions 9.0.0-M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2. The core issue lies in the org.apache.catalina.session.PersistenceManager class, which serializes and deserializes HTTP session data to disk for persistence across server restarts. When an attacker can inject a malicious serialized Java object into a session (e.g., via a crafted cookie or request parameter), the deserialization process triggers arbitrary code execution without authentication. The vulnerability was discovered by security researcher Alvaro Muñoz and reported through the Apache security team. The official advisory is available at Apache Tomcat Security Advisory.

2. Affected Versions and Exploitability

According to the Apache advisory, all Tomcat versions prior to the following are vulnerable: 9.0.99, 10.1.35, and 11.0.3. The vulnerability is exploitable when the PersistenceManager is enabled (default in some configurations using PersistentManager) and the session store is writable by the web application. Attackers can deliver the payload via HTTP request headers (e.g., Cookie: JSESSIONID=...) or through uploaded files that are later deserialized. The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network exploitability without privileges or user interaction. The NVD entry confirms this at NVD - CVE-2025-30066.

3. Attacker TTPs and MITRE ATT&CK Mapping

Attackers exploiting CVE-2025-30066 follow a classic deserialization attack chain. The primary technique maps to T1203: Exploitation for Client Execution, as the attacker delivers a malicious object that executes on the server. The initial access vector is T1190: Exploit Public-Facing Application, since Tomcat is often exposed on ports 8080 or 8443. Post-exploitation, attackers commonly deploy web shells (T1505.003: Server Software Component: Web Shell) or establish persistence via scheduled tasks (T1053.005: Scheduled Task). Additionally, they may use T1059.004: Command and Scripting Interpreter: Unix Shell for remote command execution. The exploit chain involves: (1) scanning for Tomcat instances with vulnerable versions, (2) crafting a serialized Java payload using tools like ysoserial with gadgets such as CommonsCollections or CommonsBeanutils, (3) injecting the payload into a session file via the /examples/servlets/servlet/SessionExample endpoint or similar, and (4) triggering deserialization by making a request that forces Tomcat to load the session from disk.

4. Detection: Sigma and YARA Rules

Defenders can detect exploitation attempts using the following detection rules. The Sigma rule monitors for suspicious session file modifications and deserialization exceptions in Tomcat logs.

title: Tomcat Deserialization Exploitation via Session Persistence
id: 7b8c9d0e-1f2a-3b4c-5d6e-7f8a9b0c1d2e
status: experimental
date: 2025-03-15
author: CybernytronX SOC
description: Detects exploitation of CVE-2025-30066 by monitoring for Java deserialization exceptions in Catalina logs and suspicious session file writes.
logsource:
  product: apache
  service: tomcat
  category: application
  definition: 'Requires Tomcat access logs and catalina.out'
detection:
  selection1:
    catalina.out|contains: 'java.io.InvalidClassException'
  selection2:
    catalina.out|contains: 'unable to deserialize'
  selection3:
    access.log|contains: 'POST /examples/servlets/servlet/SessionExample'
  condition: selection1 or selection2 or selection3
falsepositives:
  - Legitimate Java serialization errors (rare)
level: high

For file-based detection, use the following YARA rule to scan session files for known deserialization payloads:

rule tomcat_deserialization_cve_2025_30066 {
  meta:
    description = "Detects serialized Java payloads targeting CVE-2025-30066"
    author = "CybernytronX Threat Intel"
    date = "2025-03-15"
    reference = "https://nvd.nist.gov/vuln/detail/CVE-2025-30066"
  strings:
    $ysoserial_common = { aced0005 73720000 } // Java serialization magic header
    $gadget_common = { 636f6d2e73756e2e6f72672e6170616368652e } // com.sun.org.apache...
    $gadget_commons = { 636f6d2e6f70656e2e7365727669636573 } // com.open.services
  condition:
    $ysoserial_common at 0 and ($gadget_common or $gadget_commons)
}

5. Mitigation: Patching and Configuration Hardening

The primary mitigation is to upgrade Apache Tomcat to versions 9.0.99, 10.1.35, or 11.0.3, as per the Apache Security Advisory. If immediate patching is not possible, disable the PersistenceManager by setting persistSession to false in context.xml. Additionally, restrict access to the /examples and /manager endpoints using network ACLs or authentication. Deploy a Web Application Firewall (WAF) with rules to block requests containing Java serialization headers (e.g., Content-Type: application/x-java-serialized-object). The CISA Known Exploited Vulnerabilities Catalog has not yet listed this CVE as of March 2025, but monitoring is advised at CISA KEV.

6. Why This Matters for Defenders

CVE-2025-30066 represents a critical risk because Apache Tomcat is one of the most widely deployed Java application servers, powering everything from enterprise portals to e-commerce platforms. The exploit chain is straightforward—requiring only a crafted HTTP request—and the payload can be delivered without authentication if the vulnerable endpoints are exposed. Unlike many deserialization vulnerabilities that require specific gadget chains, this flaw leverages Tomcat's own serialization mechanism, making it more reliable for attackers. For defenders, the key takeaway is that even mature software like Tomcat can harbor overlooked deserialization flaws in seemingly innocuous components like session persistence. This reinforces the need for regular vulnerability scanning, strict least-privilege configurations, and monitoring of deserialization-related errors in logs. The exploit's simplicity and high impact make it a prime candidate for inclusion in ransomware and APT toolkits, as seen with similar Tomcat vulnerabilities in the past (e.g., CVE-2020-9484).

Sources

Frequently Asked Questions

What is the CVSS score for CVE-2025-30066?

The CVSS v3.1 base score is 9.8 (Critical), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, per the NVD entry.

Which Tomcat versions are affected?

All versions prior to 9.0.99, 10.1.35, and 11.0.3 are vulnerable. This includes mainstream releases like 9.0.98 and 10.1.34.

Can this vulnerability be exploited without authentication?

Yes, if the Tomcat server exposes vulnerable endpoints (e.g., /examples/servlets/servlet/SessionExample) without authentication. The advisory confirms unauthenticated exploitation is possible.

What is the recommended mitigation if patching is delayed?

Disable the PersistenceManager by setting persistSession=false in context.xml, restrict access to /examples and /manager endpoints, and deploy a WAF to block Java serialization content types.

Is there any evidence of active exploitation in the wild?

As of March 2025, CISA has not listed this CVE in the Known Exploited Vulnerabilities Catalog, but given the high CVSS score and ease of exploitation, active attacks are likely imminent.

How can I detect exploitation attempts?

Monitor Tomcat catalina.out logs for deserialization errors like java.io.InvalidClassException, and access logs for POST requests to /examples/servlets/servlet/SessionExample. Use the Sigma and YARA rules provided above.

Need expert help with this?

CybernytronX offers specialized penetration testing and SOC build-out services to identify and defend against vulnerabilities like CVE-2025-30066. Our Ethereon AI threat detection platform provides real-time monitoring for deserialization attacks and other advanced threats. Contact our team for a risk assessment, or learn more about Ethereon AI to strengthen your defenses today.

AK

Ammar Khan — Founder, CybernytronX

Certified Ethical Hacker (CEH), B.S. Cybersecurity, Google Certified. 5+ years pentesting, creator of Ethereon AI threat detection. Has remediated 50+ environments and recovered 20+ compromised domains. Hire CybernytronX →

← Back to all articles