<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ArcGIS Data Store : Getting vulnerability error for Tomcat in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310277#M36601</link>
    <description>&lt;P&gt;Esri don't publish the version of Tomcat that is in use.&amp;nbsp; It's black boxed and effectively becomes Esri ArcGIS Enterprise 10.9.1.&amp;nbsp; Given the age of this discussion, you may want to consider 11.1 instead of 10.9.1...&lt;/P&gt;&lt;P&gt;Sorry, I'm being blunt because I'm under the pump, but given you're running 10.6.1, I would personally be less bothered about Tomcat version and more bothered about the fact that all support for 10.6.1 stops on 31/12/2023.&amp;nbsp; You'll have an unsupported version from 1 January 24...&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en-us/products/arcgis-enterprise/life-cycle" target="_blank"&gt;https://support.esri.com/en-us/products/arcgis-enterprise/life-cycle&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jul 2023 23:17:58 GMT</pubDate>
    <dc:creator>Scott_Tansley</dc:creator>
    <dc:date>2023-07-20T23:17:58Z</dc:date>
    <item>
      <title>ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1178275#M33234</link>
      <description>&lt;P&gt;Hi Admin,&lt;/P&gt;&lt;P&gt;I am using ESRI enterprise suit 10.7.x including Geo-event Server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Out IT admin found that an older version of Tomcat for ArcGIS Data Store gives a&amp;nbsp;vulnerability alert.&lt;/P&gt;&lt;P&gt;Based on ESRI documentation found that :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Not possible to update only tomcat in ArcGIS Data Store&lt;/P&gt;&lt;P&gt;2. Need to update the entire data storage&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Let's say if we update only tomcat then it might give an error for Geo-event Server&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached is a screenshot for more details.&lt;/P&gt;&lt;P&gt;Kindly check and let us know the further steps and the best approach.&lt;BR /&gt;&lt;BR /&gt;Thanks for the support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 09:07:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1178275#M33234</guid>
      <dc:creator>jfmssupport</dc:creator>
      <dc:date>2022-05-30T09:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1178378#M33241</link>
      <description>&lt;P&gt;ArcGIS Enterprise is built of a number of software building blocks like tomcat, Java, log4J. &amp;nbsp;The wider ArcGIS code is dependent upon those versions and so they are implemented by Esri within all AGE components as a BlackBox. &amp;nbsp;Attempting to upgrade them, other than via ArcGIS upgrades would be risky and invalidate your support.&lt;/P&gt;&lt;P&gt;the best (only) way to upgrade tomcat (or any other sub component) within ArcGIS Enterprise is a full software upgrade to 10.9.1.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 20:59:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1178378#M33241</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2022-05-30T20:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310273#M36600</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/413165"&gt;@Scott_Tansley&lt;/a&gt;&amp;nbsp;I am facing the same issue: Tenable is alerting about vulnerabilities on our 10.6.1 Enterprise deployment.&lt;/P&gt;&lt;P&gt;Two Questions:&lt;/P&gt;&lt;P&gt;1- Is there documentation supporting/explaining how patches remove/mitigate Tomcat vulnerabilities? I would like to see something similar to the log4j one (we used this one to request an exception with our Security team: &lt;A href="https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam/)" target="_blank"&gt;https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/arcgis-software-and-cve-2021-44228-aka-log4shell-aka-logjam/)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;2- You suggested updating to Enterprise 10.9.1: which version of Tomcat is deployed with that ArcGIS version? I could not fin online a relation Enterprise version &amp;lt;=&amp;gt; Tomcat version.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 23:10:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310273#M36600</guid>
      <dc:creator>lpertovt</dc:creator>
      <dc:date>2023-07-20T23:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310277#M36601</link>
      <description>&lt;P&gt;Esri don't publish the version of Tomcat that is in use.&amp;nbsp; It's black boxed and effectively becomes Esri ArcGIS Enterprise 10.9.1.&amp;nbsp; Given the age of this discussion, you may want to consider 11.1 instead of 10.9.1...&lt;/P&gt;&lt;P&gt;Sorry, I'm being blunt because I'm under the pump, but given you're running 10.6.1, I would personally be less bothered about Tomcat version and more bothered about the fact that all support for 10.6.1 stops on 31/12/2023.&amp;nbsp; You'll have an unsupported version from 1 January 24...&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en-us/products/arcgis-enterprise/life-cycle" target="_blank"&gt;https://support.esri.com/en-us/products/arcgis-enterprise/life-cycle&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 23:17:58 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310277#M36601</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2023-07-20T23:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310337#M36602</link>
      <description>&lt;P&gt;Thanks for your suggestion. However, 11.x is not compatible with some tools and configurations on our system. We have already plans for an upgrade, and the January deadline is not a concern, but the Tomcat vulnerabilities are.&lt;/P&gt;&lt;P&gt;Do you know if installing 10.9.1, Tenable will still report Tomcat vulnerabilities?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 02:55:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310337#M36602</guid>
      <dc:creator>lpertovt</dc:creator>
      <dc:date>2023-07-21T02:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: ArcGIS Data Store : Getting vulnerability error for Tomcat</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310339#M36603</link>
      <description>&lt;P&gt;I can't say if a third-party piece of monitoring will or will not.&amp;nbsp; Like an anti-virus the signatures change regularly, and I guess tenable would use a similar regular update process?&amp;nbsp; Sorry.&amp;nbsp; Vulnerabilities change over time and so if I said it's okay today, it could report tomorrow.&amp;nbsp; 10.9.1 is nearly 2 years old now, so there is a chance that it could report in the not-too-distant future.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 03:02:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/arcgis-data-store-getting-vulnerability-error-for/m-p/1310339#M36603</guid>
      <dc:creator>Scott_Tansley</dc:creator>
      <dc:date>2023-07-21T03:02:35Z</dc:date>
    </item>
  </channel>
</rss>

