<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Vulnerabilities in embedded Apache Tomcat - ArcGIS Server and Portal. CVE-2025-55668, CVE-2025-48989 in ArcGIS Enterprise Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-questions/multiple-vulnerabilities-in-embedded-apache-tomcat/m-p/1643609#M42881</link>
    <description>&lt;P&gt;Could you please report these via the ArcGIS trust center:&lt;/P&gt;&lt;P&gt;&lt;A href="https://trust.arcgis.com/en/security-concern/" target="_blank"&gt;https://trust.arcgis.com/en/security-concern/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This will get you the response you need from the appropriate people.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Aug 2025 09:32:16 GMT</pubDate>
    <dc:creator>A_Wyn_Jones</dc:creator>
    <dc:date>2025-08-20T09:32:16Z</dc:date>
    <item>
      <title>Multiple Vulnerabilities in embedded Apache Tomcat - ArcGIS Server and Portal. CVE-2025-55668, CVE-2025-48989</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/multiple-vulnerabilities-in-embedded-apache-tomcat/m-p/1643604#M42880</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have ArcGIS Server 11.5 and ArcGIS Portal 11.3 in production environment with the below highlighted vulnerabilities by our organization Cyber Security Team. please need advice for the same, since i have not been able to find any patches or documents which addresses the exact same vulnerabilities for the specific ArcGIS Enterprise Versions.&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;This advisory addresses Apache Tomcat security updates addressing two major vulnerabilities, impacting several supported versions of its open-source application server. These vulnerabilities could be exploited to carry out session fixation attacks or trigger denial-of-service (DoS) using the MadeYouReset method in HTTP/2.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;CVE-2025-55668 -&amp;nbsp;Session Fixation via Rewrite Valve&lt;/STRONG&gt;&lt;BR /&gt;6.5 Medium&lt;BR /&gt;Apache Tomcat's rewrite valve mechanism contains a session fixation flaw, which could let attackers assign a session ID to a user before they log in, potentially enabling session hijacking.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;CVE-2025-48989 -&amp;nbsp;Denial-of-Service via MadeYouReset HTTP/2 Technique&lt;/STRONG&gt;&lt;BR /&gt;7.5 High&lt;BR /&gt;Apache Tomcat is susceptible to the MadeYouReset attack, which exploits the HTTP/2 protocol by mishandling stream resets, leading to resource exhaustion.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 08:43:06 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/multiple-vulnerabilities-in-embedded-apache-tomcat/m-p/1643604#M42880</guid>
      <dc:creator>vipulsoni</dc:creator>
      <dc:date>2025-08-20T08:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Vulnerabilities in embedded Apache Tomcat - ArcGIS Server and Portal. CVE-2025-55668, CVE-2025-48989</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-questions/multiple-vulnerabilities-in-embedded-apache-tomcat/m-p/1643609#M42881</link>
      <description>&lt;P&gt;Could you please report these via the ArcGIS trust center:&lt;/P&gt;&lt;P&gt;&lt;A href="https://trust.arcgis.com/en/security-concern/" target="_blank"&gt;https://trust.arcgis.com/en/security-concern/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This will get you the response you need from the appropriate people.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Aug 2025 09:32:16 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-questions/multiple-vulnerabilities-in-embedded-apache-tomcat/m-p/1643609#M42881</guid>
      <dc:creator>A_Wyn_Jones</dc:creator>
      <dc:date>2025-08-20T09:32:16Z</dc:date>
    </item>
  </channel>
</rss>

