Skip to main content
NetApp Knowledge Base

Detection of CVE-2025-24813 on NetApp console agent's container

Views:
8
Visibility:
Public
Votes:
0
Category:
cloud-manager
Specialty:
CLOUD
Last Updated:

Applies to

  • NetApp Console Agent
  • CVE 2025-24813
  • Container cloudmanager_vmservice_controlplane  (version v5.0.0-R5.0.0-SaaS-52)

Issue

  • Vulnerability scanner detected a Remote Code Execution (RCE) vulnerability (CVE-2025-24813) on the NetApp Console Agent. The specific component identified is tomcat-embed-core-10.1.34.jar located at /opt/netapp/controlplane/croproxy-0.0.1-SNAPSHOT.jar/BOOT-INF/lib/tomcat-embed-core-10.1.34.jar within a container named cloudmanager_vmservice_controlplane (version v5.0.0-R5.0.0-SaaS-52)
  • Vulnerability description:

    The vulnerability in Apache Tomcat, identified as CVE-2025-24813, allows remote code execution (RCE) via a simple PUT request, enabling attackers to gain control over servers. The flaw is due to Tomcat's handling of partial PUT requests and file-based session storage, allowing an attacker to upload a malicious Java payload that is later executed when accessed via a GET request. The exploit bypasses traditional security tools by using base64 encoding to obfuscate the payload.

    • Name: cloudmanager_vmservice_controlplane:v5.0.0-R5.0.0-SaaS-52
    • Type: Container

    CVSS score: 10.0

    CVSS severity: CRITICAL

    First seen date: 2026-05-13

    Fix available: yes

    Packages:

    Package name

    Installed version

    Patched version

    Non OS package paths

    tomcat-embed-core-10.1.34.jar (10.1.34): org.apache.tomcat.embed:tomcat-embed-core

    10.1.34

    tomcat-embed-core-10.1.34.jar (10.1.34): org.apache.tomcat.embed:tomcat-embed-core

    /opt/netapp/controlplane/croproxy-0.0.1-SNAPSHOT.jar/BOOT-INF/lib/tomcat-embed-core-10.1.34.jar

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.