Does Apache Tomcat come embedded with ArcGIS Enterprise Installation?

5204
15
Jump to solution
07-13-2021 12:29 PM
MichaelTorbett
Frequent Contributor

I have ArcGIS Enterprise 10.6.1 installed on a virtual machine with a Windows IIS Web Adapter. My network administrator recently did a security scan that shows an old version of Apache Tomcat. It either needs to be upgraded or uninstalled to be is compliance with my agency's security policy.  However, I cannot find any evidence of it being installed.  Does Apache Tomcat come embedded with ArcGIS Enterprise?

 

Thanks,

Michael

0 Kudos
15 Replies
alexanderzitzmann
Emerging Contributor

Gibt es hier schon Erkenntnisse, https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316 wird bei uns als kritisch eingestuft.

0 Kudos
JoshuaBixby
MVP Esteemed Contributor

ArcGIS Enterprise 11.4.0 has Apache Tomcat/9.0.93

vipulsoni
Regular Contributor

Hi @JoshuaBixby ,

As per Apache Tomcat (https://lists.apache.org/thread/y6lj6q1xnp822g6ro70tn19sgtjmr80r) it seems the ArcGIS Enterprise 11.4.0 is also having Vulnerable Version of embedded Tomcat installed. There are no patches from ESRI yet for this issue.

0 Kudos
alexanderzitzmann
Emerging Contributor

i downloaded latest apache-tomcat and replaced it at framework/runtime/tomcat/lib, testet on 11.2 linux, no problems so far. 

0 Kudos
George_Thompson
Esri Notable Contributor

I would go over and review this CVE on the Trust | ArcGIS site. There may be some information on this.

Also read this thread about updating tomcat outside of the ArcGIS software upgrade / patches: https://community.esri.com/t5/arcgis-enterprise-questions/apache-tomcat-vulnerability-cve-2024-50379... 

--- George T.
0 Kudos
JoshuaBixby
MVP Esteemed Contributor

As covered in Apache Tomcat vulnerability CVE-2024-50379 - Esri Community , the vulnerability is not applicable to ArcGIS Server I do not expect Esri to release a patch.

0 Kudos