Hi Mark, Thank you for the clarification, I really appreciate your help in clearing this up and confirming that upgrading to the 9.0.122 Tomcat release is the required mitigation.
Best regards, Thiru On Sat, 26 Sept, 2026, 11:33 pm Mark Thomas, <[email protected]> wrote: > Yes. It is a copy/paste error. Removing the examples (while a good thing > to do) doesn't mitigate nay of those. > > Mark > > > On 26/09/2026 11:48, Thiru wrote: > > Hi Sebastian, > > > > Thank you again for the clarification. > > > > One point I missed to mention in my earlier email is that, if this was > > indeed a copy-and-paste error in the disclosure emails, that would > explain > > the apparent inconsistency between the mitigation guidance ("Remove the > > examples web application") and the code changes associated with the > fixes, > > which appear to be in Tomcat core classes. > > > > Just to confirm my understanding: for users running production systems > > where the examples web application is not deployed, upgrading to 9.0.122 > > (or the corresponding fixed release) is still required to remediate these > > vulnerabilities, and removing the examples application alone should not > be > > considered a complete substitute for applying the fixes. Is that correct? > > > > Thank you for your time and clarification. > > > > Kind regards, > > Thiru > > > > On Sat, 26 Sept, 2026, 4:02 pm Thiru, <[email protected]> wrote: > > > >> Hi Sebastian, > >> > >> Thank you for the clarification. > >> > >> I came across these mitigation details in the vendor advisories > referenced > >> by the CVE entries linked from the Tomcat Security 9 page. > >> > >> For each of the 12 vulnerabilities, the referenced Tomcat advisory > >> includes the same mitigation guidance: > >> > >> Users of the affected versions should apply one of the following > >> mitigations: > >> > >> - *Remove the examples web application* > >> - Upgrade to Apache Tomcat 11.0.26 > >> - Upgrade to Apache Tomcat 10.1.60 > >> - Upgrade to Apache Tomcat 9.0.122 > >> > >> The advisories referenced from CVE.org are: > >> > >> - https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp > >> - https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc > >> - https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw > >> - https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz > >> - https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk > >> - https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8 > >> - https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do > >> - https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w > >> - https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg > >> - https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn > >> - https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z > >> - https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr > >> > >> To clarify, we do not deploy the examples application in our production > >> environments. My question was primarily to understand whether the > presence > >> of the examples application is actually a prerequisite for exploiting > these > >> vulnerabilities. > >> > >> When reviewing some of the associated fixes, I noticed changes in Tomcat > >> core classes rather than in the examples application itself. That is > what > >> led me to wonder whether "Remove the examples web application" is a > valid > >> mitigation for these CVEs, or whether upgrading to the fixed Tomcat > release > >> is ultimately the only effective mitigation. > >> > >> In other words, if the examples application is not deployed, should > these > >> vulnerabilities still be considered applicable to the Tomcat instance, > >> thereby requiring an upgrade to 9.0.122? > >> > >> Thank you again for your time and clarification. > >> > >> Kind regards, > >> Thiru > >> > >> > >> On Sat, Sep 26, 2026 at 1:48 PM Sebastian Trost via users < > >> [email protected]> wrote: > >> > >>> On 9/26/26 04:27, Thiru wrote: > >>>> The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low > >>>> severity). For each of these CVEs, the mitigation appears to be: > >>>> > >>>> Remove the examples web application > >>>> > >>>> [...] > >>>> > >>>> Could you please clarify whether all 12 CVEs are only exploitable > >>> through > >>>> the *examples* web application, and whether removing the examples > >>>> application alone is sufficient to mitigate these vulnerabilities > >>> without > >>>> upgrading Tomcat? > >>>> > >>>> Reference: > >>>> > >>> > https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122 > >>> Where do you see this? The only reference to removing the examples web > >>> application I can find is in the CVE disclosure mails from Mark. The > >>> "Remove the examples web application" started with his mail on July > >>> 28th, CVE-2026-66299, and continues in every other CVE disclosure. My > >>> guess is that he simply forgot to remove the "Remove the examples web > >>> application" again and this is a copy&paste mistake. > >>> > >>> Why are people so hung up about this examples web application? It > always > >>> has been best practice to remove it and the other web applications in > >>> production environments and to only deploy your own web app. > >>> > >>> Sebastian > >>> > >>> > >>> > >>> --------------------------------------------------------------------- > >>> To unsubscribe, e-mail: [email protected] > >>> For additional commands, e-mail: [email protected] > >>> > >>> > > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > >
