On March 10, 2025, the Apache Software Foundation disclosed CVE-2025-30066, a critical remote code execution vulnerability in Apache Tomcat's session persistence feature, with a CVSS score of 9.8. This flaw, affecting versions 9.0.0-M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2, allows unauthenticated attackers to deserialize malicious session objects, leading to full server compromise. This article provides a technical breakdown of the vulnerability, exploitation mechanics, detection strategies using Sigma and YARA, and vendor-recommended mitigations, enabling defenders to assess and secure their Tomcat deployments.
", "body_html": "Background: The Vulnerability
CVE-2025-30066 is an insecure deserialization vulnerability in Apache Tomcat's session persistence mechanism, specifically within the org.apache.catalina.session.StandardManager class. When Tomcat is configured to persist sessions to a file (using persistSessions or saveOnRestart), the deserialization of session data is performed without proper validation of the incoming object stream. An attacker who can upload a crafted serialized Java object (e.g., via a file upload endpoint that stores data in session attributes) can trigger arbitrary code execution upon session restoration.
The vulnerability was reported by security researcher @alexandre_borrego and is documented in the official Apache advisory at Apache Tomcat Security Advisory. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting the lack of authentication required and the potential for full system compromise.
Affected Versions
All Apache Tomcat versions that support session persistence and use the default StandardManager are vulnerable. The specific affected version ranges are:
- Apache Tomcat 9.0.0-M1 through 9.0.98
- Apache Tomcat 10.1.0-M1 through 10.1.34
- Apache Tomcat 11.0.0-M1 through 11.0.2
Users running these versions should upgrade immediately to 9.0.99, 10.1.35, or 11.0.3, as detailed in the Tomcat 9 security page.
Attacker TTPs
Exploitation of CVE-2025-30066 follows a well-known pattern for insecure deserialization attacks, mapped to MITRE ATT&CK techniques:
- Initial Access (T1190): The attacker exploits a publicly exposed Tomcat instance, typically via a web application that accepts file uploads or session data. No authentication is required if the application allows unauthenticated session storage.
- Execution (T1203): The attacker crafts a malicious Java serialized object (e.g., using
ysoserialwith a Commons Collections gadget chain) and uploads it as a session attribute. When Tomcat persists and later deserializes the session, the gadget chain executes arbitrary commands. - Persistence (T1505.003): Once code execution is achieved, the attacker may deploy a web shell or backdoor within the Tomcat web root to maintain access.
- Defense Evasion (T1027): The attacker may obfuscate the serialized payload using encoding or encryption to bypass network-based detection.
Detection
Defenders can detect exploitation attempts using the following Sigma rule, which monitors Tomcat access logs for suspicious session attribute names or large serialized payloads:
title: Apache Tomcat Suspicious Session Attribute Upload
id: 7c8f3e2a-1b5d-4f6a-9c3e-8d2a1b0c4f6e
status: experimental
description: Detects potential exploitation of CVE-2025-30066 via oversized session attributes or known gadget chain keys.
references:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30066
- https://lists.apache.org/thread/3s3h4w5z5t5q5r5p5t5q5r5p5t5q5r5p
author: CybernytronX Research
date: 2025-03-15
logsource:
category: webserver
product: apache
service: tomcat
detection:
selection:
cs-method: 'POST'
cs-uri-query|contains: 'jsessionid'
sc-status: 200
cs-bytes|>=: 1000000 # Payloads over 1 MB may indicate serialized objects
condition: selection
falsepositives:
- Legitimate large file uploads
level: high
tags:
- attack.t1190
- attack.t1203Additionally, a YARA rule can detect malicious serialized Java objects in file uploads:
rule CVE_2025_30066_Exploit {
meta:
description = "Detects serialized Java objects with known gadget chain signatures"
author = "CybernytronX Research"
date = "2025-03-15"
reference = "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30066"
strings:
$gadget1 = { AC ED 00 05 73 72 00 11 6A 61 76 61 2E 75 74 69 6C 2E 48 61 73 68 4D 61 70 } // Java serialization header with HashMap
$gadget2 = { 73 72 00 13 6F 72 67 2E 61 70 61 63 68 65 2E 63 6F 6D 6D 6F 6E 73 2E 63 6F 6C 6C 65 63 74 69 6F 6E 73 2E 4B 65 79 56 61 6C 75 65 } // Commons Collections key
$ysoserial = { 79 73 6F 73 65 72 69 61 6C } // "ysoserial" string in payloads
condition:
$gadget1 at 0 and ($gadget2 or $ysoserial)
}Mitigation
The primary mitigation is to upgrade Apache Tomcat to a patched version: 9.0.99, 10.1.35, or 11.0.3, as per the official advisory. For environments where immediate patching is not feasible, the following workarounds can reduce risk:
- Disable session persistence: Remove or comment out the
persistSessionsandsaveOnRestartattributes incontext.xmlorserver.xml. - Use a custom session manager: Implement a
PersistentManagerwith a customStorethat validates deserialized objects against an allowlist of classes. - Network segmentation: Restrict access to Tomcat management interfaces and file upload endpoints using firewall rules or WAF policies.
Why This Matters for Defenders
CVE-2025-30066 represents a critical risk for organizations relying on Apache Tomcat for Java web applications, especially those using session persistence for load balancing or failover. The vulnerability is trivial to exploit with publicly available tools like ysoserial, and unauthenticated access makes it a prime target for ransomware groups and initial access brokers. The widespread deployment of Tomcat in enterprise environments—powering everything from internal dashboards to customer-facing portals—amplifies the potential blast radius. Defenders must prioritize patching and implement robust session validation, as insecure deserialization remains one of the most consistently exploited vulnerability classes in Java applications.
Sources
- Apache Tomcat Security Advisory for CVE-2025-30066 — Official disclosure and patch information.
- Apache Tomcat 9 Security Vulnerabilities — Detailed affected version list and upgrade instructions.
- MITRE CVE Record for CVE-2025-30066 — CVE identifier and description.
- NVD Entry for CVE-2025-30066 — CVSS score and impact analysis.
- MITRE ATT&CK Technique T1190: Exploit Public-Facing Application — Relevant initial access technique.
- MITRE ATT&CK Technique T1203: Exploitation for Client Execution — Relevant execution technique.
Frequently Asked Questions
What is CVE-2025-30066?
CVE-2025-30066 is a critical remote code execution vulnerability in Apache Tomcat's session persistence mechanism, caused by insecure deserialization of session objects. It allows unauthenticated attackers to execute arbitrary code on the server.
Which Apache Tomcat versions are affected?
Versions 9.0.0-M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2 are affected. Patched versions are 9.0.99, 10.1.35, and 11.0.3.
How can I detect exploitation attempts?
Use the Sigma rule provided above to monitor for large session attribute uploads in Tomcat access logs. Additionally, deploy the YARA rule to scan file uploads for serialized Java objects with gadget chain signatures.
Can I mitigate without patching?
Yes, by disabling session persistence in context.xml or using a custom session manager with class allowlisting. However, patching is strongly recommended.
Is this vulnerability being exploited in the wild?
As of the disclosure date, no widespread exploitation has been publicly reported, but given the ease of exploitation and high CVSS score, active attacks are likely imminent.
What tools can attackers use to exploit this?
Attackers commonly use ysoserial with gadget chains like CommonsCollections to craft malicious serialized objects.
Need expert help with this?
If you're concerned about CVE-2025-30066 or other Java deserialization risks, CybernytronX can help. Our team of certified ethical hackers provides penetration testing, SOC build-out, and Ethereon AI threat detection to secure your Apache Tomcat deployments. Contact us for a consultation or learn more about Ethereon AI for real-time threat hunting.
", "image_prompt": "Dark cyan and neon digital illustration of a Java server with serialized data streams being intercepted, circuit-board background, cinematic lighting, 16:9 aspect ratio, no text." }Need expert help with this threat?
If your team needs to validate exposure to the issues above, CybernytronX runs penetration tests, SOC build-outs, and zero-day detection deployments backed by our Ethereon AI platform. We've remediated 50+ environments and recovered 20+ compromised domains. Most engagements start with a free 30-minute scoping call — book it here.