[midPoint] Tomcat 8 vulnerability

Radovan Semancik radovan.semancik at evolveum.com
Thu Oct 12 14:21:27 CEST 2017


Hi,

I'm running on Tomcat 8.5.* almost since it was released and I have seen 
no problem so far. I think I have even tried running from support-3.4 
branch on Tomcat 8.5.*, but I'm not 100% sure. However, I'm not aware of 
any obstacle for running midPoint 3.4 on tomcat 8.5.*. It is worth trying.

-- 
Radovan Semancik
Software Architect
evolveum.com



On 10/12/2017 12:58 PM, Roman Pudil - AMI Praha a.s. wrote:
> Hi all,
>
> we have midPoint 3.4 on Windows Server 2012 R2 and Tomcat 8.5.4 listed 
> in https://wiki.evolveum.com/display/midPoint/Release+3.4.1. But this 
> Tomcat version has vulnerability 
> http://www.cvedetails.com/cve/CVE-2016-8735/.
>
> We have to upgrade Tomcat 8 to higher version (currently 8.5.23).
>
> Has anybody experience with Tomcat 8.5.7 (or higher) and MidPoint 3.4?
>
> Thanks!
>
> Regards
>
> Roman Pudil
> solution architect
>
> gsm: [+420] 775 663 666
> e-mail:roman.pudil at ami.cz <mailto:roman.pudil at ami.cz>
>
> 			
>
> AMI Praha a.s.
> Pláničkova 11
> 162 00 Praha 6
> tel./fax: [+420] 274 783 239
> web:www.ami.cz <http://www.ami.cz>
>
> 			
>
>
> <http://www.ami.cz/reseni-a-sluzby/bezpecnost-dat/identity-management>
>
> Textem tohoto e-mailu podepisující neslibuje uzavřít ani neuzavírá za 
> společnost AMI Praha a.s.
> jakoukoliv smlouvu. Každá smlouva, pokud bude uzavřena, musí mít 
> výhradně písemnou formu.
>
>
>
>
> _______________________________________________
> midPoint mailing list
> midPoint at lists.evolveum.com
> http://lists.evolveum.com/mailman/listinfo/midpoint


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.evolveum.com/pipermail/midpoint/attachments/20171012/ec399942/attachment.htm>


More information about the midPoint mailing list