Hi Tomcat Team,

I have a question regarding the security vulnerabilities disclosed in the
Tomcat 9.0.122 release.

The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
severity). For each of these CVEs, the mitigation appears to be:

Remove the examples web application

However, when reviewing the commit links associated with the CVEs, the
fixes appear to have been implemented in core Tomcat classes rather than
solely within the examples application.

Could you please clarify whether all 12 CVEs are only exploitable through
the *examples* web application, and whether removing the examples
application alone is sufficient to mitigate these vulnerabilities without
upgrading Tomcat?

Reference:
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122

Thank you for your time and clarification.
Kind regards,
Thiru

Reply via email to