<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache Tomcat vulnerability CVE-2024-50379 in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573169#M41339</link>
    <description>&lt;P&gt;I get that. I hear it from customers frequently. However, this is an out-of-date approach and is inconsistent with CISA's guidance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CISA's approach has been for organizations to provide what's called an SBOM - a Software Bill of Materials. The SBOM is a machine-readable document that lists all of the "ingredients" used to build software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to the fact that the SBOM will surface issues like this that have no practical impact on a product, CISA also provides a way to justify the presence of a vulnerability that does not actually impact software - a similar limit that automated security tooling has. To account for that, CISA provides a tool to justify the presence of these vulns - that's CISA's VEX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisa.gov/sites/default/files/publications/VEX_Use_Cases_Document_508c.pdf" target="_blank" rel="noopener"&gt;Vulnerability Exploitability eXchange (VEX) – Use Cases&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisa.gov/sites/default/files/publications/VEX_Status_Justification_Jun22.pdf" target="_blank" rel="noopener"&gt;Vulnerability Exploitability eXchange (VEX) - Status Justifications&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Additionally, we strongly encourage customers to leverage tools like &lt;A href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_self"&gt;CISA's KEV catalog.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;KEV provides an authoritative source of vulnerabilities that are known to have been exploited "in the wild".&amp;nbsp;CVE-2024-50379 is not (yet) listed in the KEV catalog.&lt;/P&gt;&lt;P&gt;For this case, the VEX status justification is "Vulnerable_code_cannot_be_controlled_by_adversary" because there's not a way for an attacker to exploit this CVE in our software. This is the direction the industry is moving - away from patching due to CVSS (which is not an indicator of risk) and toward using limited resources to address issues that introduce risk - eg: demonstrably exploitable issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we update Tomcat for each release and our 11.5 release will include an updated internal application server, we have no plans to offer an out-of-cycle patch for a CVE that does not impact ArcGIS Enterprise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a case like this, when organizations threaten to take a service offline to satisfy a "compliance" requirement when a vendor - who is authoritative in this discussion - provides evidence that the issue is not exploitable, the organization in fact causes a high severity (CVSSv31 7.5) denial of service against themselves. We welcome additional conversation regarding our vulnerability handling process. Feel free to shoot me a DM and we can arrange a discussion with your CISO and other stakeholders.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2025 16:12:53 GMT</pubDate>
    <dc:creator>RandallWilliams</dc:creator>
    <dc:date>2025-01-07T16:12:53Z</dc:date>
    <item>
      <title>Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1569975#M41268</link>
      <description>&lt;P&gt;We're already getting pinged by our IT for a security vulnerability with Apache Tomcat released 12/17/24 - CVE-2024-50379.&amp;nbsp; I am operating on 11.3.&amp;nbsp; Assume I just need to wait for a patch to be released?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat allows for Remote Code Execution (RCE) on case insensitive file systems when the default servlet is enabled for write. This vulnerability affects Apache Tomcat versions 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, and 9.0.0.M1 through 9.0.97. An attacker can exploit this vulnerability to execute arbitrary code. It is recommended to upgrade to version 11.0.2, 10.1.34, or 9.0.08 to fix this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Impact: If this vulnerability is exploited, an attacker can execute arbitrary code on the affected system, potentially leading to a complete compromise of the system.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remediation: Apply the latest patches and updates provided by the respective vendors.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Dec 2024 21:18:46 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1569975#M41268</guid>
      <dc:creator>JohnLivengood</dc:creator>
      <dc:date>2024-12-18T21:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1570224#M41275</link>
      <description>&lt;P&gt;This is actually an interesting question, because, They announced deprecation of ArcGIS Maps SDK for Java in march of 2024.&amp;nbsp;&amp;nbsp;&lt;A href="https://support.esri.com/en-us/knowledge-base/arcgis-maps-sdk-for-java-deprecation-000032164" target="_blank"&gt;https://support.esri.com/en-us/knowledge-base/arcgis-maps-sdk-for-java-deprecation-000032164&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;also noted with the notice at the top of this page:&amp;nbsp;&lt;A href="https://developers.arcgis.com/java/" target="_blank"&gt;https://developers.arcgis.com/java/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;So if Java is not being used as an integration point, what other parts of ArcGIS that we may be deploying actually rely on Java and or Tomcat?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2024 16:10:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1570224#M41275</guid>
      <dc:creator>TimWestern</dc:creator>
      <dc:date>2024-12-19T16:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1570749#M41280</link>
      <description>&lt;P&gt;Apache tomcat has released an update to&amp;nbsp;&lt;SPAN&gt;CVE-2024-50379&lt;/SPAN&gt;.&amp;nbsp; Follow at your own peril but I downloaded the latest 9.0.98 jar file and renamed to tomcat-juli.jar.&amp;nbsp; On each server I replaced the vulnerable jar file with the latest version.&amp;nbsp; After restarting the 3 enterprise services, everything is working normally and scans are clear.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details on the vulnerability&amp;nbsp;&lt;A href="https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98" target="_blank"&gt;Apache Tomcat® - Apache Tomcat 9 vulnerabilities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Downloadable repository&amp;nbsp;&lt;A href="https://repo.maven.apache.org/maven2/org/apache/tomcat/tomcat-juli/9.0.98/" target="_blank"&gt;Central Repository: org/apache/tomcat/tomcat-juli/9.0.98&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I would still recommend waiting for the official patch but if you're in a hurry...&lt;/P&gt;</description>
      <pubDate>Fri, 20 Dec 2024 21:27:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1570749#M41280</guid>
      <dc:creator>JohnLivengood</dc:creator>
      <dc:date>2024-12-20T21:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573137#M41336</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;While automated vulnerability scanners will complain about&amp;nbsp;&lt;SPAN&gt;CVE-2024-50379, this CVE has no impact on ArcGIS software. A challenge with almost all of these tools is that they are good at comparing a given software product/version against a database of known vulnerabilities, they are typically unable to validate exploitability.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In this case, Esri software is not impacted by&amp;nbsp;&lt;SPAN&gt;CVE-2024-50379 because we do not configure the default servlet to enable write (readonly initialisation parameter set to the non-default value of false). We also don't enable the PUT method at the application server level.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Note also that this CVE would typically only impact Windows - Linux based file systems are case sensitive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2025 15:54:45 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573137#M41336</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-01-22T15:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573139#M41337</link>
      <description>&lt;P&gt;John, this is a dangerous, untested, and unsupported path. We do not bundle the default, unmodified Tomcat binaries with ArcGIS software. It is likely that vulnerabilities that do not impact ArcGIS software due to how we build Tomcat are now introduced by this change. We strongly recommend against in-place upgrades of 3rd party components used in our software.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 15:02:33 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573139#M41337</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-01-07T15:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573154#M41338</link>
      <description>&lt;P&gt;Believe me I understand that but telling our IT security team "it's likely that the vulnerabilities do not impact us" is not a solution.&amp;nbsp; They wanted to shut down our enterprise system entirely until a patch was released.&amp;nbsp; I work for a State Gov Agency, and they don't mess around with these scans.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Esri working on a patch?&amp;nbsp; The good news is I stored the old jar files on an external drive.&amp;nbsp; My plan is to place them back when a patch is released.&amp;nbsp; But for now, everything appears to be working normally.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 15:50:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573154#M41338</guid>
      <dc:creator>JohnLivengood</dc:creator>
      <dc:date>2025-01-07T15:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573169#M41339</link>
      <description>&lt;P&gt;I get that. I hear it from customers frequently. However, this is an out-of-date approach and is inconsistent with CISA's guidance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CISA's approach has been for organizations to provide what's called an SBOM - a Software Bill of Materials. The SBOM is a machine-readable document that lists all of the "ingredients" used to build software.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to the fact that the SBOM will surface issues like this that have no practical impact on a product, CISA also provides a way to justify the presence of a vulnerability that does not actually impact software - a similar limit that automated security tooling has. To account for that, CISA provides a tool to justify the presence of these vulns - that's CISA's VEX.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisa.gov/sites/default/files/publications/VEX_Use_Cases_Document_508c.pdf" target="_blank" rel="noopener"&gt;Vulnerability Exploitability eXchange (VEX) – Use Cases&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisa.gov/sites/default/files/publications/VEX_Status_Justification_Jun22.pdf" target="_blank" rel="noopener"&gt;Vulnerability Exploitability eXchange (VEX) - Status Justifications&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Additionally, we strongly encourage customers to leverage tools like &lt;A href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_self"&gt;CISA's KEV catalog.&lt;/A&gt;&lt;/P&gt;&lt;P&gt;KEV provides an authoritative source of vulnerabilities that are known to have been exploited "in the wild".&amp;nbsp;CVE-2024-50379 is not (yet) listed in the KEV catalog.&lt;/P&gt;&lt;P&gt;For this case, the VEX status justification is "Vulnerable_code_cannot_be_controlled_by_adversary" because there's not a way for an attacker to exploit this CVE in our software. This is the direction the industry is moving - away from patching due to CVSS (which is not an indicator of risk) and toward using limited resources to address issues that introduce risk - eg: demonstrably exploitable issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;While we update Tomcat for each release and our 11.5 release will include an updated internal application server, we have no plans to offer an out-of-cycle patch for a CVE that does not impact ArcGIS Enterprise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In a case like this, when organizations threaten to take a service offline to satisfy a "compliance" requirement when a vendor - who is authoritative in this discussion - provides evidence that the issue is not exploitable, the organization in fact causes a high severity (CVSSv31 7.5) denial of service against themselves. We welcome additional conversation regarding our vulnerability handling process. Feel free to shoot me a DM and we can arrange a discussion with your CISO and other stakeholders.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 16:12:53 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573169#M41339</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-01-07T16:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573182#M41340</link>
      <description>&lt;P&gt;Welcome to State Government.&amp;nbsp; We thrive on out-of-date approaches.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 16:25:28 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1573182#M41340</guid>
      <dc:creator>JohnLivengood</dc:creator>
      <dc:date>2025-01-07T16:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1574838#M41383</link>
      <description>&lt;P&gt;For completeness - ^^^ This same response also applies to&amp;nbsp;&lt;SPAN&gt;&lt;A title="https://nvd.nist.gov/vuln/detail/cve-2024-56337" href="https://nvd.nist.gov/vuln/detail/CVE-2024-56337" target="_blank" rel="noreferrer noopener"&gt;CVE-2024-56337&lt;/A&gt;&amp;nbsp;. These are basically the same bugs, but the&amp;nbsp;mitigation for CVE-2024-50379 was incomplete. We have recently updated our 3rd party CVE response app to reflect the above stance for&amp;nbsp;CVE-2024-50379. That app is found in the "Customer Exclusive" document repository in the ArcGIS Trust Center.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 15:49:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1574838#M41383</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-01-13T15:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596624#M41835</link>
      <description>&lt;P&gt;Randall, can we assume the same holds true (no impact) for&amp;nbsp;&lt;A title="https://nvd.nist.gov/vuln/detail/CVE-2025-24813" href="https://nvd.nist.gov/vuln/detail/CVE-2025-24813" target="_self"&gt;CVE-2025-24813&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 16:08:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596624#M41835</guid>
      <dc:creator>Jay_Geisen</dc:creator>
      <dc:date>2025-03-18T16:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596648#M41836</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/299136"&gt;@Jay_Geisen&lt;/a&gt;&amp;nbsp;Correct. All of these issues require that the Tomcat application server be configured to allow writes to the default servlet, which is disabled by default (and we don't enable). We also don't enable PUT or partial PUT. These facts can be validated with a quick look at our web.xml file.&amp;nbsp;&lt;/P&gt;&lt;P&gt;SOAPBOX:&lt;/P&gt;&lt;P&gt;This kind of issue is representative of the fact that automated vuln scanners provide super-high levels of false positives. They simply enumerate component versions and compare against a list of vulnerabilities in a database, but don't typically have the ability to actually validate their findings OR provide context. I understand why: a false positive is better than a false negative. The challenge comes when organizations take these findings as absolute truth, when the scan vendors provide clear statements that they do NOT validate based on context, just component version. That leaves many users in a weird spot, where a vendor like Esri says "we're not impacted" but the automated tool says, "...therefore the software is vulnerable".&lt;/P&gt;&lt;P&gt;/SOAPBOX&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 17:27:40 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596648#M41836</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-03-18T17:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596669#M41839</link>
      <description>&lt;P&gt;Thank you for the clarification - much appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 17:07:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596669#M41839</guid>
      <dc:creator>Jay_Geisen</dc:creator>
      <dc:date>2025-03-18T17:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596670#M41840</link>
      <description>&lt;P&gt;I do appreciate your responses.&amp;nbsp; This new CVE came across my desk and I was able to respond in kind based on the previous CVE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'll continue have these false positive scans.&amp;nbsp; No way around it as our Office of Cyber Security team is in a completely separate agency and each State Agency receives a vulnerability score based on these scans.&amp;nbsp; They are willing to close out select vulnerabilities, but it takes a bit of thrashing back and forth.&amp;nbsp; Most of us administrators may not know where and how to look at the server's susceptibility.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this instance, your help has been very much appreciated and thanks for the tip about the web.xml.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 17:07:57 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596670#M41840</guid>
      <dc:creator>JohnLivengood</dc:creator>
      <dc:date>2025-03-18T17:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596684#M41842</link>
      <description>&lt;P&gt;I frequently hold conversations with security stakeholders on this topic. Hit us up using the form on &lt;A href="https://trust.arcgis.com" target="_blank"&gt;https://trust.arcgis.com&lt;/A&gt;&amp;nbsp;if we can help provide context to security teams. Usually when I talk to "security", they get where I'm coming from. "Compliance" is a whole 'nother can o' worms. If it helps, we update major frameworks like Java, Tomcat, PostGREs with each release. We have a clear history of addressing vulnerabilities - wherever they come from - if they are exploitable. We don't take these things lightly and have vested interest in ensuring we provide safe software. We just take a measured, risk-based approach to make sure we use our limited resources in the most effective manner. For instance, no, we don't plan to patch Tomcat for this issue, but that's because we have issues that are clearly exploitable to manage. We can publicly attest to that fact here:&amp;nbsp;&lt;A href="https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;amp;results_type=overview&amp;amp;search_type=all&amp;amp;isCpeNameSearch=false&amp;amp;cpe_vendor=cpe%3A%2F%3Aesri" target="_blank"&gt;https://nvd.nist.gov/vuln/search/results?form_type=Advanced&amp;amp;results_type=overview&amp;amp;search_type=all&amp;amp;isCpeNameSearch=false&amp;amp;cpe_vendor=cpe%3A%2F%3Aesri&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 17:34:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1596684#M41842</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-03-18T17:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597352#M41866</link>
      <description>&lt;P&gt;&lt;A href="https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/recent-apache-tomcat-rce-vulnerabilities/" target="_blank" rel="noopener"&gt;Recent Apache Tomcat RCE Vulnerabilities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Esri just posted about that one and says we are not vulnerable to the exploit.&lt;/P&gt;&lt;P&gt;I checked our 11.3 server and it running Tomcat 9.0.84.&amp;nbsp; Can someone check what version 11.4 has?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 23:33:22 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597352#M41866</guid>
      <dc:creator>MichaelJenkins</dc:creator>
      <dc:date>2025-03-19T23:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597559#M41869</link>
      <description>Portal for ArcGIS and ArcGIS Server use Tomcat 9.0.93 at 11.4&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Mar 2025 15:08:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597559#M41869</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-03-20T15:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597562#M41870</link>
      <description>&lt;P&gt;Correct. There is no exploit path for this and other CVEs in ArcGIS Enterprise. In order to be vulnerable, someone with local access must have rights to the ArcGIS Enterprise installation and modify configuration files. If an attacker has local access to a machine and can make these changes, the victim has much bigger vulnerabilities they need to address.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 15:11:47 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1597562#M41870</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-03-20T15:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1610058#M42114</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp; Is the same true for this&amp;nbsp;CVE-2025-24813?&amp;nbsp; This one shows up on the KEV&amp;nbsp;&lt;A href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-24813&amp;amp;field_date_added_wrapper=all&amp;amp;field_cve=&amp;amp;sort_by=field_date_added&amp;amp;items_per_page=20&amp;amp;url=" target="_blank"&gt;Known Exploited Vulnerabilities Catalog | CISA&amp;nbsp; :&amp;nbsp;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-24813&amp;amp;field_date_added_wrapper=all&amp;amp;field_cve=&amp;amp;sort_by=field_date_added&amp;amp;items_per_page=20&amp;amp;url=&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 16:26:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1610058#M42114</guid>
      <dc:creator>JeffGilmour</dc:creator>
      <dc:date>2025-04-29T16:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1610105#M42119</link>
      <description>&lt;P&gt;Yes, we speak to all three&amp;nbsp;Recent Apache Tomcat RCE Vulnerabilities&amp;nbsp;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2025-24813" target="_blank" rel="noopener"&gt;CVE-2025-24813&lt;/A&gt;&lt;SPAN&gt;, &amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2024-50379" target="_blank" rel="noopener"&gt;CVE-2024-50379&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2024-56337" target="_self"&gt;CVE-2024-56337&lt;/A&gt;&amp;nbsp;together in this advisory:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/recent-apache-tomcat-rce-vulnerabilities" target="_blank" rel="noopener"&gt;https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/recent-apache-tomcat-rce-vulnerabilities&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Some teams require a higher level of detail and assurance to understand why these CVEs don't impact ArcGIS Enterprise.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get deep in the weeds on why CVE-2025-24813 has no impact on ArcGIS Enterprise:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The team should first understand the CVE: &lt;A href="https://nvd.nist.gov/vuln/detail/CVE-2025-24813" target="_blank" rel="noopener"&gt;NVD - CVE-2025-24813&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;The team should understand this writeup: &lt;A href="https://www.petefreitag.com/blog/tomcat-writes-enabled/" target="_blank" rel="noopener"&gt;Understanding and Checking for Tomcat CVE-2025-24813&lt;/A&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;CVE text:&lt;/P&gt;&lt;P&gt;Title: Path Equivalence: 'file.Name' (Internal Dot) leading to&amp;nbsp;Remote Code Execution and/or Information disclosure&amp;nbsp;and/or malicious content added to uploaded files via write enabled&amp;nbsp;Default Servlet&amp;nbsp;in Apache Tomcat.&lt;/P&gt;&lt;P&gt;***********************************************&lt;/P&gt;&lt;P&gt;&amp;nbsp;Impacted versions: This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.&lt;/P&gt;&lt;P&gt;Impact statement: &lt;STRONG&gt;If all of the following were true&lt;/STRONG&gt;, a malicious user was able to view security sensitive files and/or inject content into those files:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;-&amp;nbsp;writes enabled for the default servlet (&lt;U&gt;disabled by default)&lt;/U&gt; &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- support for partial PUT (enabled by default)&lt;/P&gt;&lt;P&gt;- a target URL for security sensitive uploads that was a sub-directory of&amp;nbsp;a target URL for public uploads&lt;/P&gt;&lt;P&gt;-&amp;nbsp;attacker knowledge of the names of security sensitive files being&amp;nbsp;uploaded&lt;/P&gt;&lt;P&gt;-&amp;nbsp;the security sensitive files also being uploaded via partial PUT&lt;/P&gt;&lt;P&gt;If all of the following were true, a malicious user was able to perform remote code execution: &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;- &lt;EM&gt;writes enabled for the default servlet (&lt;U&gt;disabled by default&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;) -&amp;nbsp;support for partial PUT (enabled by default)&lt;/P&gt;&lt;P&gt;-&amp;nbsp;application was using Tomcat's file-based session persistence with the&amp;nbsp;default storage location&lt;/P&gt;&lt;P&gt;-&amp;nbsp;application included a library that may be leveraged in a&amp;nbsp;deserialization attack&lt;/P&gt;&lt;P&gt;Users are recommended to upgrade to version 11.0.3, 10.1.35 or 9.0.99, which fixes the issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;*********************************&lt;/P&gt;&lt;P&gt;Esri Detail:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;The non-default parameter “readonly” needs to be explicitly set. Not setting this value does not indicate vulnerability. Tomcat doesn’t set this option at all because there’s rarely a reason to enable write on the default servlet. &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Proof:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Compare the default, out of the box Tomcat’s web.xml, which again is not vulnerable by default against the Esri implementation. You will not see a directive to setting “readonly:false” in our implementation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RandallWilliams_0-1745948385983.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/131117i76CFC57216A426E4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RandallWilliams_0-1745948385983.png" alt="RandallWilliams_0-1745948385983.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here’s a link to download the default OOTB Tomcat : &lt;A href="https://dlcdn.apache.org/tomcat/tomcat-10/v10.1.40/bin/apache-tomcat-10.1.40.tar.gz" target="_blank" rel="noopener"&gt;https://dlcdn.apache.org/tomcat/tomcat-10/v10.1.40/bin/apache-tomcat-10.1.40.tar.gz&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here’s a complete writeup to fully substantiate our assertions:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.petefreitag.com/blog/tomcat-writes-enabled/" target="_blank" rel="noopener"&gt;Understanding and Checking for Tomcat CVE-2025-24813&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here’s an OPTIONS request indicating that the PUT method is not enabled (&lt;STRONG&gt;&lt;EM&gt;writes are NOT enabled for the default servlet (&lt;U&gt;disabled by default).&lt;/U&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RandallWilliams_1-1745948385987.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/131118i01D49D8113DCADD3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RandallWilliams_1-1745948385987.png" alt="RandallWilliams_1-1745948385987.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here’s an open source scanner than can check for this issue:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/issamjr/CVE-2025-24813-Scanner" target="_blank" rel="noopener"&gt;GitHub - issamjr/CVE-2025-24813-Scanner: CVE-2025-24813 - Apache Tomcat Vulnerability Scanner&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RandallWilliams_2-1745948385992.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/131119i6B002F96DB6BFD8B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RandallWilliams_2-1745948385992.png" alt="RandallWilliams_2-1745948385992.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We have updated our 3rd party component CVE response application to include our responses to these CVEs. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 17:43:08 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1610105#M42119</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-04-29T17:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Tomcat vulnerability CVE-2024-50379</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1624186#M42419</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;sorry to ping you again on this topic, do you have information about&amp;nbsp;CVE-2025-31650?&lt;/P&gt;&lt;P&gt;I was notified about CVE-2025-31650 in our Portal and Server 11.3 servers, the Tomcat developers have marked this as "important" and fixed it in Tomcat 9.0.104:&amp;nbsp;&lt;A href="https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.104" target="_blank" rel="noopener"&gt;https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.104&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As of now I can't find entries in the KVE database and Esri CVE Responses, but exploits are linked on e.g. the Snyk CVE database.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt; I was informed that Portal and Server 11.3 are not affected by this vulnerability. It would require the use of HTTP/2 which is not configured on the embedded Tomcats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 16:47:56 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379/m-p/1624186#M42419</guid>
      <dc:creator>ChristophK</dc:creator>
      <dc:date>2025-06-18T16:47:56Z</dc:date>
    </item>
  </channel>
</rss>

