On 9/26/26 04:27, Thiru wrote:
The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
severity). For each of these CVEs, the mitigation appears to be:

Remove the examples web application

[...]

Could you please clarify whether all 12 CVEs are only exploitable through
the *examples* web application, and whether removing the examples
application alone is sufficient to mitigate these vulnerabilities without
upgrading Tomcat?

Reference:
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
Where do you see this? The only reference to removing the examples web application I can find is in the CVE disclosure mails from Mark. The "Remove the examples web application" started with his mail on July 28th, CVE-2026-66299, and continues in every other CVE disclosure. My guess is that he simply forgot to remove the "Remove the examples web application" again and this is a copy&paste mistake.

Why are people so hung up about this examples web application? It always has been best practice to remove it and the other web applications in production environments and to only deploy your own web app.

Sebastian



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to