<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tomcat Security Vulnerabilities in Developers Questions</title>
    <link>https://community.esri.com/t5/developers-questions/tomcat-security-vulnerabilities/m-p/554761#M3732</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question involves the version of Tomcat bundled into the latest versions of the ArcGIS Server and Portal products (7.x.x.x).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; I am new to supporting ArcGIS for my employer, and have come into the picture after a failed attempt to update Tomcat on our ArcGIS server.&amp;nbsp;&amp;nbsp; This broke ArcGIS completely.&amp;nbsp; Today, we are in process of reinstalling "Server" and "Portal", federation, and the whole enchilada - it has been a&amp;nbsp;disaster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My employer runs Qualys scans internally -&amp;nbsp;scans which pick up vulverable software versions (windows patches needed or old versions of Java, even outdated versions of Tomcat!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We try to make sure we are not running software which is known to have security problems.&amp;nbsp; Here at the Bank, my job is to find ways to update everything to latest versions if possible.&amp;nbsp; &lt;STRONG&gt;The lowest or oldest version of Tomcat that our bank will support is &lt;SPAN style="font-size: 11pt;"&gt;8.5.15 &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; **MY QUESTION: Is it possible for the DEV team at ESRI to drop in (at least) Tomcat 8.5.15 into a TEST build (bundle or compile the installer with the latest -- or at least 8.5.15) and see if that would work just as well as 7.x.x.x?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please consider carving out some time to test&amp;nbsp;out a modified installer package for me.&amp;nbsp; I really would like to know if it would be that painful for the DEV team to&amp;nbsp;give it a try.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;Thanks in advance,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;Greg Wei, Wells Fargo Bank (San Francisco)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 May 2017 23:00:41 GMT</pubDate>
    <dc:creator>GregoryWei</dc:creator>
    <dc:date>2017-05-04T23:00:41Z</dc:date>
    <item>
      <title>Tomcat Security Vulnerabilities</title>
      <link>https://community.esri.com/t5/developers-questions/tomcat-security-vulnerabilities/m-p/554761#M3732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My question involves the version of Tomcat bundled into the latest versions of the ArcGIS Server and Portal products (7.x.x.x).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; I am new to supporting ArcGIS for my employer, and have come into the picture after a failed attempt to update Tomcat on our ArcGIS server.&amp;nbsp;&amp;nbsp; This broke ArcGIS completely.&amp;nbsp; Today, we are in process of reinstalling "Server" and "Portal", federation, and the whole enchilada - it has been a&amp;nbsp;disaster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My employer runs Qualys scans internally -&amp;nbsp;scans which pick up vulverable software versions (windows patches needed or old versions of Java, even outdated versions of Tomcat!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; We try to make sure we are not running software which is known to have security problems.&amp;nbsp; Here at the Bank, my job is to find ways to update everything to latest versions if possible.&amp;nbsp; &lt;STRONG&gt;The lowest or oldest version of Tomcat that our bank will support is &lt;SPAN style="font-size: 11pt;"&gt;8.5.15 &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; **MY QUESTION: Is it possible for the DEV team at ESRI to drop in (at least) Tomcat 8.5.15 into a TEST build (bundle or compile the installer with the latest -- or at least 8.5.15) and see if that would work just as well as 7.x.x.x?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please consider carving out some time to test&amp;nbsp;out a modified installer package for me.&amp;nbsp; I really would like to know if it would be that painful for the DEV team to&amp;nbsp;give it a try.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;Thanks in advance,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11pt;"&gt;Greg Wei, Wells Fargo Bank (San Francisco)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 23:00:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/developers-questions/tomcat-security-vulnerabilities/m-p/554761#M3732</guid>
      <dc:creator>GregoryWei</dc:creator>
      <dc:date>2017-05-04T23:00:41Z</dc:date>
    </item>
  </channel>
</rss>

