VTS25-007
CISA Known Exploited Vulnerability: Apache Tomcat Path Equivalence Vulnerability
Revision History
- 1.0: April 15, 2025: Initial Version
Summary
Veritas is aware of the critical path equivalence vulnerability in Apache Tomcat (CVE-2025-24813) that was added to the CISA Known Exploited Vulnerability Catalog on April 01, 2025 (Known Exploited Vulnerabilities Catalog | CISA). All Veritas Product Security and Development teams are currently reviewing our software to determine if the vulnerability exists in any of our products, and we will update the advisory as we gather more information.
Veritas Product | Status |
Access Appliance | Not Vulnerable |
IT Analytics | Under Investigation |
Alta Data Protection | Not Vulnerable |
Alta Recovery Vault | Not Vulnerable |
Alta SaaS Protection | Not Vulnerable |
Alta View | Not Vulnerable |
NetBackup | Not Vulnerable |
NetBackup Appliance | Not Vulnerable |
NetBackup Flex Appliance | Not Vulnerable |
NetBackup Flex Scale | Not Vulnerable |
NetBackup OpsCenter | Not Vulnerable |
NetBackup Resiliency Platform | Not Vulnerable |
NetBackup Self Service | Not Vulnerable |
NetBackup Snapshot Manager | Not Vulnerable |
NetInsights Console | Not Vulnerable |
Disclaimer
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Cohesity, Inc.
2625 Augustine Dr
Santa Clara, CA 95054