CVE-2025-49125 | Apache Tomcat up to 9.0.105/10.1.41/11.0.7 authentication bypass (EUVD-2025-18406 / Nessus ID 240060)
A vulnerability classified as critical was found in Apache Tomcat up to 9.0.105/10.1.41/11.0.7. This impacts an unknown function. Such manipulation leads to authentication bypass using alternate channel.
This vulnerability is uniquely identified as CVE-2025-49125. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.