Need confirmation about CVE-2025-55754.
"Charpe, Anil" <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <PH7PR17MB608112139C2491A8385A3E0ABEF9A@PH7PR17MB6081.namprd17.prod.outlook.com> |
Hi, It is about the CVE-2025-55754<https://nvd.nist.gov/vuln/detail/CVE-2025-55754> mentioned in the email subject. I have a couple of question to confirm since when I googled it mentions that - Yes, exploiting CVE-2025-55754 requires user interaction and relies on an administrator running an interactive command console. So, it is creating confusion and ambiguity as to what is exactly correct ? Kindly clarify & confirm. * Is this CVE applicable only when there is an interactive console ? * If there is interactive console but then if Tomcat is launched from that console in altogether a separate Window just like a process monitor, then will this CVE still be applicable ? Thanks & Regards,