# CVE-2025-24813-noPoC
After countless hours I was unable to come up with any real PoC.
While the deserialization of uploaded files *could* pose a threat, all payload-chains I tested failed.
Tested on versions 9.0.90 and 10.1.15 of Apache Tomcat
**Nothing else to see here!**
SEVERE [http-nio-8080-exec-5] org.apache.catalina.core.StandardHostValve.invoke Exception Processing /
java.lang.RuntimeException: IllegalAccessException: java.lang.IllegalAccessException: class org.apache.commons.beanutils.PropertyUtilsBean cannot access class com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl (in module java.xml) because module java.xml does not export com.sun.org.apache.xalan.internal.xsltc.trax to unnamed module @7c53a9eb
SEVERE [http-nio-8080-exec-2] org.apache.catalina.core.StandardHostValve.invoke Exception Processing /
org.apache.commons.collections.FunctorException: InvokerTransformer: The method 'newTransformer' on 'class com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl' cannot be accessed
...
[4.0K] /data/pocs/4f7d026c0904e635b7e2a4f690f122ff21c48e2c
└── [1.0K] README.md
0 directories, 1 file